Splunk Search

Splunk custom script with python and pip library | Integrity check of installed files failed

GaetanVP
Contributor

Hello Splunkers,

I recently created a custom alerts on my Search Head, and for this alert to run I needed to install a Pip library (here HttpNtlmAuth).

I used this command : 

/opt/splunk/bin/python3.7 -m pip install <my_package>

Afterwards my script & alert just ran correctly but the health check "Integrity check of installed files" failed because of this install (Splunk is complaining that my python bin and lib have changed, some other are missing).

I have read that I can install manually the Python package, but I would have the same integrity check problems right ?

Thanks for your answers,
GaetanVP

Tags (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Just like one can upgrade Splunk without losing any configurations, one can re-install the same version without losing any configurations.  Backup $SPLUNK_HOME/etc to be safe.

You also can restore the individual files you overwrote by extracting them from the Splunk tarball.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You're getting the integrity check messages because you altered the files that came with Splunk.  The fix is to re-install Splunk so you have the original file set.

Avoid the problem by putting the HttpNtimAuth library (and any others you need that do not come with Splunk) in the lib directory of your custom app.

---
If this reply helps you, Karma would be appreciated.

GaetanVP
Contributor

Thanks for your answer @richgalloway, I will try that !
About the re-install Splunk, I would definitely lose some configuration / files and so on... right ? No way to fixed the issue within s Splunk tool / cli ?

Thanks.
GaetanVP

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Just like one can upgrade Splunk without losing any configurations, one can re-install the same version without losing any configurations.  Backup $SPLUNK_HOME/etc to be safe.

You also can restore the individual files you overwrote by extracting them from the Splunk tarball.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...