Getting Data In

unexpectedly installed a another instance of splunk on the Linux server on the same path,but the service is not started yet for the new installation.how to get it removed.

Pavithrapavi
Engager

ran rpm -e on search head and then ran rpm -I --prefix=
Now if I run ./splunk from splunk/bin folder, I am unable to run.its asking me to accept the license , if I accept the license then its saying that splunkd must be stopped to migrate

Tags (1)
0 Karma
1 Solution

traxxasbreaker
Communicator

Sounds like you did an inadvertent upgrade. What version were you on before and what version did you install with rpm? Most likely the way to get rid of it would be to reapply the older version from an rpm repo with that version. If it's the same version, then the migration will likely do nothing... Either way you should probably stop Splunk first then restart it afterward.

You can also try accepting the license and then it should prompt you to either do a dry run showing what it would change or just let it run the migration. If you do the dry run, that would give you a chance to see if it's actually going to change anything and go to a new version or if you just got the current version into a weird state.

View solution in original post

traxxasbreaker
Communicator

Sounds like you did an inadvertent upgrade. What version were you on before and what version did you install with rpm? Most likely the way to get rid of it would be to reapply the older version from an rpm repo with that version. If it's the same version, then the migration will likely do nothing... Either way you should probably stop Splunk first then restart it afterward.

You can also try accepting the license and then it should prompt you to either do a dry run showing what it would change or just let it run the migration. If you do the dry run, that would give you a chance to see if it's actually going to change anything and go to a new version or if you just got the current version into a weird state.

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...