<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Remote Upgrader for Linux Universal Forwarders from Deployment Server in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/756004#M29753</link>
    <description>&lt;P&gt;&lt;BR /&gt;tail -15f upgrade.log&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking insensitive config: MONITOR_PKG_INTERVAL_SEC=&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking insensitive config: FWD_UPGRADE_TIMEOUT_SEC=&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking insensitive config: FWD_UPGRADE_MAX_RETRY=&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking insensitive config: ROTATE_HISTORY_LOG_DAYS=&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking sensitive config: SPLUNK_UPDATER_USER=&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking sensitive config: SPLUNK_UPDATER_GROUP=&lt;BR /&gt;2025-12-01-11:11:01 INFO Checking insensitive config: SPLUNK_HOME=/opt/splunkforwarder&lt;BR /&gt;2025-12-01-11:11:01 INFO Validating config SPLUNK_HOME=/opt/splunkforwarder&lt;/P&gt;</description>
    <pubDate>Mon, 01 Dec 2025 12:07:03 GMT</pubDate>
    <dc:creator>msmadhu</dc:creator>
    <dc:date>2025-12-01T12:07:03Z</dc:date>
    <item>
      <title>Splunk Remote Upgrader for Linux Universal Forwarders from Deployment Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/753499#M29703</link>
      <description>&lt;P&gt;We are attempting to upgrade Splunk Universal Forwarders using the UF Remote Upgrade Add-on.&lt;/P&gt;&lt;P&gt;As per Splunk documentation, we have installed the add-on, placed the required upgrade packages in the appropriate directories and pushed the app to the target clients via the Deployment Server. However, the upgrade is not taking place and we are seeing the following error in the log file located at /opt/splunk/var/log/splunk/upgrader_package_delivery.log:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Error log from&amp;nbsp; /opt/splunk/var/log/splunk/upgrader_package_delivery.log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2025-09-22-14:22:10 Conf file from UF updater does not exist at "/opt/splunk/var/run/splunk/splunkupdater/info". The UF updater is likely not installed or running.&lt;/P&gt;&lt;P&gt;2025-09-22-14:22:10 Cancelling package delivery and waiting for next interval.&lt;/P&gt;&lt;P&gt;2025-09-22-14:23:10 Checking if any forwarder packages are available&lt;/P&gt;&lt;P&gt;2025-09-22-14:23:10 Found files in /opt/splunk/etc/deployment_apps/splunk_app_uf_remote_upgrade_linux/bin/../local/packages. Will deliver them.&lt;/P&gt;&lt;P&gt;splunk_app_uf_remote_upgrade_linux/&lt;BR /&gt;├── bin&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── SPLUNK_UPDATER_INTERNAL_deliver_pkg.sh&lt;BR /&gt;├── default&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── app.conf&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── inputs.conf&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── local_config&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── packages&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── splunk-upgrader-linux-102.tgz&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── splunk-upgrader-linux-102.tgz.sig&lt;BR /&gt;├── local&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── app.conf&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── local_config.bkp&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── packages&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── splunkforwarder-10.0.0-e8eb0c4654f8-linux-amd64.tgz&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── splunkforwarder-10.0.0-e8eb0c4654f8-linux-amd64.tgz.sha512&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── splunkforwarder-10.0.0-e8eb0c4654f8-linux-amd64.tgz.sig&lt;BR /&gt;├── metadata&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── local.meta&lt;BR /&gt;└── VERSION&lt;/P&gt;&lt;P&gt;Note: Splunk enterprise is running with version 10.0.0 and UF is running with 9.4.2&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 15:06:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/753499#M29703</guid>
      <dc:creator>msmadhu</dc:creator>
      <dc:date>2025-09-23T15:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Remote Upgrader for Linux Universal Forwarders from Deployment Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/753510#M29704</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248816"&gt;@msmadhu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you confirm you have configured the remote update service on the remote UF as per the docs at&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/splunk-remote-upgrader-for-linux-universal-forwarders/9.4/quickstart-guide/quickstart-guide" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/splunk-remote-upgrader-for-linux-universal-forwarders/9.4/quickstart-guide/quickstart-guide&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Please could you post the output of:&amp;nbsp;&lt;SPAN&gt;systemctl status splunk-upgrader &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you? If so, please consider&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 21:41:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/753510#M29704</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-09-23T21:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Remote Upgrader for Linux Universal Forwarders from Deployment Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/753540#M29705</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Pushed UF upgrade files from Deployment server to UF and same files are reflecting in UF, but not upgraded&lt;BR /&gt;&lt;BR /&gt;No, service is not running,&lt;BR /&gt;&lt;BR /&gt;systemctl status splunk-upgrader.service&lt;BR /&gt;Unit splunk-upgrader.service could not be found.&lt;BR /&gt;&lt;BR /&gt;UF:&lt;/P&gt;&lt;P&gt;[root@xyz apps]# tree splunk_app_uf_remote_upgrade_linux/&lt;BR /&gt;splunk_app_uf_remote_upgrade_linux/&lt;BR /&gt;├── bin&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── pkg_delivered&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── SPLUNK_UPDATER_INTERNAL_deliver_pkg.sh&lt;BR /&gt;├── default&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── app.conf&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── inputs.conf&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── local_config&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── packages&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── splunk-upgrader-linux-102.tgz&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── splunk-upgrader-linux-102.tgz.sig&lt;BR /&gt;├── local&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── app.conf&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── packages&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── checksums.txt&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── splunkforwarder-10.0.0-e8eb0c4654f8-linux-amd64.tgz&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; ├── splunkforwarder-10.0.0-e8eb0c4654f8-linux-amd64.tgz.sha512&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── splunkforwarder-10.0.0-e8eb0c4654f8-linux-amd64.tgz.sig&lt;BR /&gt;├── metadata&lt;BR /&gt;│&amp;nbsp;&amp;nbsp; └── local.meta&lt;BR /&gt;└── VERSION&lt;/P&gt;&lt;P&gt;6 directories, 14 files&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/bin/splunk version&lt;BR /&gt;Warning: Attempting to revert the SPLUNK_HOME ownership&lt;BR /&gt;Warning: Executing "chown -R splunk:splunk /opt/splunkforwarder"&lt;BR /&gt;Splunk Universal Forwarder 9.4.2 (build e9664af3d956)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 12:12:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/753540#M29705</guid>
      <dc:creator>msmadhu</dc:creator>
      <dc:date>2025-09-24T12:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Remote Upgrader for Linux Universal Forwarders from Deployment Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/755994#M29752</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;● splunk-upgrader.service - Splunk Upgrader daemon that monitors for new UF packages to upgrade to&lt;BR /&gt;Loaded: loaded (/etc/systemd/system/splunk-upgrader.service; enabled; vendor preset: disabled)&lt;BR /&gt;Active: failed (Result: exit-code) since Mon 2025-12-01 11:11:01 UTC; 40s ago&lt;BR /&gt;Process: 2011130 ExecStart=/opt/splunkupgrader/bin/splunk_updater_launcher.sh (code=exited, status=1/FAILURE)&lt;BR /&gt;Main PID: 2011130 (code=exited, status=1/FAILURE)&lt;/P&gt;&lt;P&gt;Dec 01 11:11:01 xyz systemd[1]: splunk-upgrader.service: Service RestartSec=100ms expired, scheduling restart.&lt;BR /&gt;Dec 01 11:11:01 xyz systemd[1]: splunk-upgrader.service: Scheduled restart job, restart counter is at 5.&lt;BR /&gt;Dec 01 11:11:01 xyz systemd[1]: Stopped Splunk Upgrader daemon that monitors for new UF packages to upgrade to.&lt;BR /&gt;Dec 01 11:11:01 xyz systemd[1]: splunk-upgrader.service: Start request repeated too quickly.&lt;BR /&gt;Dec 01 11:11:01 xyz systemd[1]: splunk-upgrader.service: Failed with result 'exit-code'.&lt;BR /&gt;Dec 01 11:11:01 xyz systemd[1]: Failed to start Splunk Upgrader daemon that monitors for new UF packages to upgrade to.&lt;BR /&gt;&lt;BR /&gt;drwxrwxrwx. 7 splunkupgrader splunkupgrader 88 May 23 2025 splunkupgrader&lt;BR /&gt;&lt;BR /&gt;2025-12-01-11:14:57 Found files in /opt/splunkforwarder/etc/apps/splunk_app_uf_remote_upgrade_linux/bin/../local/packages. Will deliver them.&lt;BR /&gt;2025-12-01-11:14:57 Conf file from UF updater does not exist at "/opt/splunkupdater/info". The UF updater is likely not installed or running.&lt;BR /&gt;2025-12-01-11:14:57 Cancelling package delivery and waiting for next interval.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 11:16:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/755994#M29752</guid>
      <dc:creator>msmadhu</dc:creator>
      <dc:date>2025-12-01T11:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Remote Upgrader for Linux Universal Forwarders from Deployment Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/756004#M29753</link>
      <description>&lt;P&gt;&lt;BR /&gt;tail -15f upgrade.log&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking insensitive config: MONITOR_PKG_INTERVAL_SEC=&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking insensitive config: FWD_UPGRADE_TIMEOUT_SEC=&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking insensitive config: FWD_UPGRADE_MAX_RETRY=&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking insensitive config: ROTATE_HISTORY_LOG_DAYS=&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking sensitive config: SPLUNK_UPDATER_USER=&lt;BR /&gt;2025-12-01-11:11:00 INFO Checking sensitive config: SPLUNK_UPDATER_GROUP=&lt;BR /&gt;2025-12-01-11:11:01 INFO Checking insensitive config: SPLUNK_HOME=/opt/splunkforwarder&lt;BR /&gt;2025-12-01-11:11:01 INFO Validating config SPLUNK_HOME=/opt/splunkforwarder&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 12:07:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/756004#M29753</guid>
      <dc:creator>msmadhu</dc:creator>
      <dc:date>2025-12-01T12:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Remote Upgrader for Linux Universal Forwarders from Deployment Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/756008#M29754</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Could u plz help on the fix,&lt;BR /&gt;&lt;BR /&gt;splunk_updater_launcher.sh[2216934]: /opt/splunkupgrader/bin/splunk_updater_launcher.sh: line 14: SPLUNK_HOME: unbound variable&lt;BR /&gt;systemd[1]: splunk-upgrader.service: Main process exited, code=exited, status=1/FAILURE&lt;BR /&gt;systemd[1]: splunk-upgrader.service: Failed with result 'exit-code'.&lt;BR /&gt;systemd[1]: splunk-upgrader.service: Service RestartSec=100ms expired, scheduling restart.&lt;BR /&gt;systemd[1]: splunk-upgrader.service: Scheduled restart job, restart counter is at 5.&lt;BR /&gt;systemd[1]: Stopped Splunk Upgrader daemon that monitors for new UF packages to upgrade to.&lt;BR /&gt;systemd[1]: splunk-upgrader.service: Start request repeated too quickly.&lt;BR /&gt;systemd[1]: splunk-upgrader.service: Failed with result 'exit-code'.&lt;BR /&gt;systemd[1]: Failed to start Splunk Upgrader daemon that monitors for new UF packages to upgrade to.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 12:54:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Remote-Upgrader-for-Linux-Universal-Forwarders-from/m-p/756008#M29754</guid>
      <dc:creator>msmadhu</dc:creator>
      <dc:date>2025-12-01T12:54:59Z</dc:date>
    </item>
  </channel>
</rss>

