Getting Data In

AIX update to splunk 5 not doing anything



Have attempted to update to version 5 this morning and it's not doing anything... I've used truss to check all the process and they are just sleeping??

root 21561516 28836070   0 08:39:08  pts/4  0:00 splunkd rest --noauth GET /services/admin/localapps/SplunkDeploymentMonitor
root 28770370 26542126   0 08:39:03  pts/4  0:00 ./splunk start
root 28836070 28770370   0 08:39:07  pts/4  0:00 python -u /opt/splunk/lib/python2.7/site-packages/splunk/clilib/ _py_internal first-time-run -is-fresh-install false -dry-run false -log-file /opt/splunk/var/log/splunk/migration.log.2012-10-31.08-39-07
root 29491430 20447408   0 08:58:08  pts/2  0:00 grep splunk

/opt/splunk/var/log/splunk # truss -p 28836070
_poll(0x0000000000000000, 0, 0) (sleeping...)

I've left it for an hour now and it's not doing anything... Any ideas?

Here is the log output

Do you agree with this license? [y/n]: y

This appears to be an upgrade of Splunk.

Splunk has detected an older version of Splunk installed on this machine. To
finish upgrading to the new version, Splunk's installer will automatically
update and alter your current configuration files. Deprecated configuration
files will be renamed with a .deprecated extension.

You can choose to preview the changes that will be made to your configuration
files before proceeding with the migration and upgrade:

If you want to migrate and upgrade without previewing the changes that will be
made to your existing configuration files, choose 'y'.
If you want to see what changes will be made before you proceed with the
upgrade, choose 'n'.

Perform migration and upgrade without previewing configuration changes? [y/n] y

-- Migration information is being logged to '/opt/splunk/var/log/splunk/migration.log.2012-10-31.08-39-07' --

Migrating to:

Copying '/opt/splunk/etc/myinstall/splunkd.xml' to '/opt/splunk/etc/myinstall/splunkd.xml-migrate.bak'.

Checking saved search compatibility...

Handling deprecated files...

Checking script configuration...

Copying '/opt/splunk/etc/myinstall/splunkd.xml.cfg-default' to '/opt/splunk/etc/myinstall/splunkd.xml'.
Deleting '/opt/splunk/etc/system/local/field_actions.conf'.

Could not find new UI modules directory to install
The following apps might contain lookup table files that are not exported to other apps:


Such lookup table files could only be used within their source app. To export them globally and allow other apps to access them, add the following stanza to each /opt/splunk/etc/apps//metadata/local.meta file:

    export = system

For more information, see

Tags (1)

Re: AIX update to splunk 5 not doing anything


Even a fresh install hangs at /opt/splunk/bin/splunkd valiatedb

Guess I'll have to wait for the next point release 😞

0 Karma

Re: AIX update to splunk 5 not doing anything

Super Champion

From the Known Issues:

Splunk on AIX hangs on first time run (SPL-58929). To work around this issue, add the following to $SPLUNK_HOME/etc/splunk-launch.conf: SPLUNK_IGNORE_ICU_TIMEZONES=1. Do not add this setting unless you are experiencing the hanging issue.

View solution in original post