Splunk Search

Python 2.7 present and shouldn't be

cmuesing
Explorer

I am getting an integrity check error on /opt/splunk/bin/python2.7 that says present_but_shouldnt_be. I can find the write protected file python2.7 in that path. Is this just as simple as deleting it? Is there some uninstall I need to run? 

Labels (1)
0 Karma
1 Solution

dural_yyz
Builder

Extracting Splunk 9.3.0 on a linux build I see a file in the /opt/splunk/ called splunk-9.3.0-<buildhash>-linux-2.6-x86_64-manifest.  That file lists every directory and file along with permission codes that should exist for your install.  The integrity checks are based upon that manifest file.  If you have a 2.7 folder still inside your install you should be safe to delete it, especially if the folder has zero hidden or displayed files/folders.

View solution in original post

sadiq_aziz
Loves-to-Learn Lots

same having this issue when we upgraded to 9.2.3

looks like Splunk installation files installed python 2.7 by default

0 Karma

dural_yyz
Builder

Extracting Splunk 9.3.0 on a linux build I see a file in the /opt/splunk/ called splunk-9.3.0-<buildhash>-linux-2.6-x86_64-manifest.  That file lists every directory and file along with permission codes that should exist for your install.  The integrity checks are based upon that manifest file.  If you have a 2.7 folder still inside your install you should be safe to delete it, especially if the folder has zero hidden or displayed files/folders.

cmuesing
Explorer

Thank you. I deleted the file and it worked great. 

computermathguy
Path Finder

We just upgraded from 9.2.2 to 9.2.3 and started getting the python integrity warnings.

 
File path                              Check result                                File path                                         Check result
/opt/splunk/bin/jp.pypresent_but_shouldnt_be/opt/splunk/bin/python2.7
present_but_shouldnt_be 
 
0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...