All Apps and Add-ons

Splunk App for Microsoft Exchange: How to get the the app to pass all the prerequisites?

gomezcl
New Member

Hello,

I am new to splunk and i installed the Exchange App and got all the prerequisites done except the first one that asks for v6.2.0 I have the newest version installed but it will not pass the test since Key Value store must be enabled. I checked in the server.conf file and it is enabled so I'm not sure what else to do. Anyone know how to get the exchange app to pass all the prerequisites?


0 Karma

malmoore
Splunk Employee
Splunk Employee

I've seen this problem occur in test environments.

Are you running this in a nix environment? If so, this is likely a permissions issue, and if it is what I think it is, we might need to file a bug. It *might have been fixed in 6.2.1, so give that a try first.

Here's what's going on:

  1. KV store is enabled by default. The problem is, one of the files in the distribution has permissions that are too lax.
  2. When the KV store service starts up, it finds that this file has bad permissions, and then only fails with an error message to $SPLUNK_HOME/var/log/splunk/mongod.log:

    2014-12-18T15:39:43.555Z permissions on /opt/splunk-dash/var/lib/splunk/kvstore/mongo/splunk.key are too open

  3. In order to fix the problem and ensure that KV store is running, you need to change the permissions of this file so that the KV store service doesn't complain and not start.

To fix this:

From a shell (or Terminal window), issue

chmod 700 /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key

Restart Splunk and run the guided setup on the Exchange app again.

ChrisG
Splunk Employee
Splunk Employee

Wait...are you saying you are not running Splunk Enterprise 6.2? Or are you saying you are running 6.2.1?

0 Karma

gomezcl
New Member

Do you have a link to the download page? I just downloaded this 2 days ago. Not sure why i didn't get the latest download??

0 Karma

ChrisG
Splunk Employee
Splunk Employee

The download link is: http://www.splunk.com/download

6.2.1 was released yesterday. 🙂

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Are you using a free license for Splunk Enterprise? There was a defect in 6.2.0 that KV store didn't work with the free license. That is fixed in 6.2.1.

gomezcl
New Member

Im running 6.2.0

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...