Getting Data In

Error during Splunk forwarder upgrade from 7.2.0 to 8.1.0

ramshan
New Member

Getting below error after executing below command 

./splunk start --accept-license --answer-yes


It seems that the Splunk default certificates are being used. If certificate validation is turned on using the default certificates (not-recommended), this may result in loss of communication in mixed-version Splunk environments after upgrade.

"/base_app/splunk/splunkforwarder/etc/auth/ca.pem": already a renewed Splunk certificate: skipping renewal
"/base_app/splunk/splunkforwarder/etc/auth/cacert.pem": already a renewed Splunk certificate: skipping renewal
ERROR: Valid migration mode not specified.
ERROR while running migrate-distsearch-conf migration.

Labels (1)
0 Karma

amanve
Engager

It's been a long time. But did any one got any answers. I am stuck with same issue on aix machine. Trying to upgrade my forwarder from 8.2.3 to 9.2.3 version

 

0 Karma

dsanders80
Loves-to-Learn Lots

Did anyone ever offer any answer to this issue.  I am running into the same problem.

0 Karma
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...