Getting Data In

Error during Splunk forwarder upgrade from 7.2.0 to 8.1.0

ramshan
New Member

Getting below error after executing below command 

./splunk start --accept-license --answer-yes


It seems that the Splunk default certificates are being used. If certificate validation is turned on using the default certificates (not-recommended), this may result in loss of communication in mixed-version Splunk environments after upgrade.

"/base_app/splunk/splunkforwarder/etc/auth/ca.pem": already a renewed Splunk certificate: skipping renewal
"/base_app/splunk/splunkforwarder/etc/auth/cacert.pem": already a renewed Splunk certificate: skipping renewal
ERROR: Valid migration mode not specified.
ERROR while running migrate-distsearch-conf migration.

Labels (1)
0 Karma

amanve
Engager

It's been a long time. But did any one got any answers. I am stuck with same issue on aix machine. Trying to upgrade my forwarder from 8.2.3 to 9.2.3 version

 

0 Karma

dsanders80
Loves-to-Learn Lots

Did anyone ever offer any answer to this issue.  I am running into the same problem.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...