IHAC with a C13 SVA instance, I recently upgraded them from Splunk MLTK 5.x to Splunk AI Toolkit 6.0.2 to modernise and neutralise the recently published CVE exposure. Splunk Enterprise is on version 10.2.6 on RHEL 8 so all recent and properly up-to-date. You also have a dependency of the 'Splunk_SA_Scientific_Python_linux_x86_64' with this new version. At first there was a problem pushing the large bundle for the SA from the SH Deployer to the SHC, and I received the following error which is easily solvable in the same way that a large ES image install is fixed: Error while deploying apps to target=https://<server>:8089 with members=3: Error while updating app=Splunk_SA_Scientific_Python_linux_x86_64 on target=https://<server>:8089: Non-200/201 status_code=413; {\"messages\":[{\"type\":\"ERROR\",\"text\":\"Content-Length of 2147496687 too large (maximum is 2147483648)\"}]}, Error while updating app=Splunk_SA_Scientific_Python_linux_x86_64 on target=https://<server>:8089: Non-200/201 status_code=413; {\"messages\":[{\"type\":\"ERROR\",\"text\":\"Content-Length of 2147496687 too large (maximum is 2147483648) Fix 1: Updated the Search Head TA and pushed this from the deployer after temporarily removing the SA from the deployment folder. I ended up making the changes on the deployer and the SH as it didn't work the first time and nothing lost web.conf [settings] max_upload_size = 4096 This change got me further forward but it would still not allow the large push and I saw a new error. I also noted the the size on disk on the Deployer was approx. 3.6GB and on the SHC 1.5GB. Error while deploying apps to target=https://<server>:8089 with members=3: Error while updating app=Splunk_SA_Scientific_Python_linux_x86_64 on target=https://<server>:8089: Error in JSON response: Unexpected EOF, Error while updating app=Splunk_SA_Scientific_Python_linux_x86_64 on target=https://<server>:8089: Error in JSON response: Unexpected EOF Fix 2: update server.conf and http stanza: server.conf [httpServer] max_content_length = 5000000000 I did make a silly mistake here and had a zero missing making it 0.5GB upload as opposed to 5GB. After that the push worked and the error message on the dependency in the UI went away (the message related to the requirement for the Splunk_SA_Scientific_Python). Final problem: I am unable to see any models in the UI, my understanding is that the models are just the .csv files in the lookups folder in the AI toolkit app, but I have not personally been the end user. - I updated app.conf on the deployer for the AI toolkit and added: deployer_lookups_push_mode =always_overwrite - This did push the updated csv's and I can see all the dates match. - I have checked the docs and I can only see remediation action required for windows - It could conceivably be related to RBAC, but I've change one item and I'm not seeing a difference as an admin. - I have also just noticed that there is a new version as of 25 August, I will upgrade to that to eliminate possible problems: Splunk AI Toolkit | Splunkbase
... View more