Thank you for your answer. I tried that but after restarting Splunk I still not see any data coming. If I perform a search I cannot get any data after the upgrade. I have 300+ scripts running every minute. Any ideas?
Using the bundles directory had been deprecated since at least version 4.0 (possibly 3.4 or earlier), though it did continue to work through 4.1. As of 4.2, you should use etc/apps/<appname>/local instead of etc/bundles/local. If you're not prepared to work with apps, you can simply copy the contents of etc/bundles to etc/apps/bundles.