Upgrade Splunk from 6.1.3 to the Latest version
There are generic documents regrading Splunk Upgrade. I am looking for a more detailed one. Are there any documents with proper steps/instructions to follow? We have a one search head, three indexers ,...
View ArticleAccess Splunk Web
I inherited a [mostly] working Splunk 6.2.2 multi server test environment which I am in the process of upgrading to 6.2.3. Search Head seems to have gone fine, same with Index Master but the Indexers...
View ArticleAfter upgrading the Cisco Networks App and Add-on for Splunk Enterprise to...
Hello; I've recently upgraded Cisco Networks App for Splunk Enterprise to cisco_ios 2.3.0, shortly followed by an upgrade to the TA on my Universal Forwarder and Indexers to TA-cisco_ios 2.3.0. My UF...
View ArticleAfter upgrading from Splunk 6.2.3 to 6.3.0, why am I getting renew-certs...
Hi, I was doing an upgrade from Splunk 6.2.3 to 6.3.0. Installation went fine, but when I start Splunk for the first time, I'm getting the error below: ERROR: "/opt/splunk/etc/auth/ca.pem.default": not...
View ArticleUpgrading a multisite indexer cluster from 6.2.x to 6.3, can I perform the...
I was reading through the upgrade documentation and came across a statement mentioning that I have to stop all peers and search head to perform the upgrade. My concern is that I will have to stop...
View ArticleUpgrade to Splunk 6.3 on Windows is failing with no useful error messages
I'm upgrading our environment from 6.2.6 to 6.3.0 on Windows (2012 R2) We have 1 x master, 3 x indexers and 1 x search head/deployment server. Trying to upgrade the master first (nothing else has been...
View ArticleHow to upgrade Splunk 6.1.3 to the latest version for a standalone instance...
Hi I have read the documentation provided in Splunk, but I just want the step by step commands to run on a Linux server from start to end since I don't have much knowledge in Linux. Also, does it...
View ArticleAre there recommendations for upgrading a search head and indexer clustering...
Trying to work through building our first cluster. I really do not have any data that is that "important", but due to labor time to build it to this stage, am a bit hesitant to fire off a mass upgrade...
View ArticleComplicated splunk upgrade & migration
I've searched and seen a few migration threads, but my setup is a bit strange. Two physical servers, 1st running splunk search head in /opt/splunk_sh, a splunk indexer in /opt/splunk_ind, and the...
View ArticleAdditional Information concerning Issue SPL-107200
Hi, where can I get additional information about Issue SPL-107200 (http://docs.splunk.com/Documentation/Splunk/6.3.0/ReleaseNotes/KnownIssues). I am planning to update a quite large Splunk environment...
View ArticleAfter upgrading Windows forwarders from Splunk 6.1.1 to 6.3, why are we...
We recently started trying to upgrade our Windows forwarder installations from 6.1.1 to 6.3, after the upgrade, the Forwarder management page states the forwarder has errors installing. The...
View ArticleIs there any need to upgrade the Universal Forwarder for Linux ARM (Raspberry...
I have installed Splunk Enterprise 6.3. The Universal Forwarder at my pi has version 1.0. Is there any need to upgrade the forwarder? thx
View ArticleIs there a test license available to install the Splunk App for Enterprise...
For those that have the Splunk App for Enterprise Security, per documentation, it is advised to test the upgrade on a test system particularly if dealing with load balanced indexers. Is there a test...
View ArticleWith our current Splunk 6.0.4 deployment and architecture, what version...
To all the Splunk Gurus, I have been looking forward to upgrading splunk from Splunk 6.0.4 (build 207768) to the latest stable release. We have a distributed environment of 2 heavy fwds (in HA), 4...
View ArticleWhy my app is not upgrading/updating?
I used to develop in an old server splunk instance and deliver it to the oficial server instance by exporting the app. Then, we had to change the old server to a new server, but all backups were made...
View ArticleUpgrade Enterprise Security from 3.3.x to 4.0 hangs on "Disabling Apps"
I am doing an upgrade of Enterprise Security from 3.3.1 to 4.0 through the GUI. I installed the app by providing it the file, then started the "Post-Install Configuration". It moves through the first...
View ArticleCan I upgrade my Linux universal forwarders directly from Splunk 6.0.3 to 6.3.0?
Hello, Just checking to see if it is okay to upgrade my Linux universal forwarders directly from 6.0.3 to 6.3.0 or if I need to make an intermediary jump. Thanks.
View ArticleAfter upgrade from 6.2 to 6.3.0 data takes longer to be searchable or data...
Hi all, I have upgraded from 6.2 to 6.3.0 and now I am finding that data is appearing much later in searches. Indeed, sometimes no new data from several sources is not found at all in which cases...
View ArticleAfter upgrading to Splunk 6.3, why am I getting a "Found...
I'm getting the following error after I upgraded to Splunk 6.3: Search peer Splunk has the following message: Found stanza=_blocksignature in indexes.conf. The block-signing feature is no longer...
View ArticleDuring custom application upgrades, is there a configuration to limit what...
I have a custom application that does incremental loads from an external resource. I maintain a file with the latest timestamps so that each run I can read the file and pull the new data. My struggle...
View Article