Getting Data In

unexpectedly installed a another instance of splunk on the Linux server on the same path,but the service is not started yet for the new installation.how to get it removed.

Pavithrapavi
Engager

ran rpm -e on search head and then ran rpm -I --prefix=
Now if I run ./splunk from splunk/bin folder, I am unable to run.its asking me to accept the license , if I accept the license then its saying that splunkd must be stopped to migrate

Tags (1)
0 Karma
1 Solution

traxxasbreaker
Communicator

Sounds like you did an inadvertent upgrade. What version were you on before and what version did you install with rpm? Most likely the way to get rid of it would be to reapply the older version from an rpm repo with that version. If it's the same version, then the migration will likely do nothing... Either way you should probably stop Splunk first then restart it afterward.

You can also try accepting the license and then it should prompt you to either do a dry run showing what it would change or just let it run the migration. If you do the dry run, that would give you a chance to see if it's actually going to change anything and go to a new version or if you just got the current version into a weird state.

View solution in original post

traxxasbreaker
Communicator

Sounds like you did an inadvertent upgrade. What version were you on before and what version did you install with rpm? Most likely the way to get rid of it would be to reapply the older version from an rpm repo with that version. If it's the same version, then the migration will likely do nothing... Either way you should probably stop Splunk first then restart it afterward.

You can also try accepting the license and then it should prompt you to either do a dry run showing what it would change or just let it run the migration. If you do the dry run, that would give you a chance to see if it's actually going to change anything and go to a new version or if you just got the current version into a weird state.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...