I know this was probably answered before, but I am not able to find any answers...
I am trying to install the Splunk UF on a Linux server after having to manually uninstall it because of overlapping 7.2.3 (.tgz) and 8.1.0 (.rpm) packages. I am trying to install the 8.1.0 rpm but get the error that it is already installed. When I try to uninstall it since the error says it's installed, then it says that it is already installed. I can't reboot the server because of operations, but would like to have Splunk operational and reporting to the indexer. Can anyone help with guidance on how to overcome this error?
Thank you for any assistance that can be provided.
I ran ps -ef and it shows splunk started. There is nothing that showed it stopped.
Okay, I look at the splunkd and metric logs, but what do I look for? All signs point that it is working, but nothing is reaching the indexer. The last time this server had even communicated was 1/6/21, but there was no metrics being sent. So that is what started me on chasing this rabbit, down the hole and found the two splunk installs...
splunkd.log shows that everything seems to be working fine. In the metrics log, it seems that there is nothing collected and sent, but not really sure about it. I did find that there is this line that makes it seem that it is trying to communicate with the indexer and DS.
INFO StatusMgr - destHost=<ip>, destIp=<ip>, destPort=9997, eventType=connect_try, publisher=Tcpout, sourcePort=8089, statusee=TCPOutputProcessor
INFO StatusMgr - destHost=<ip>, destIp=<ip>, destPort=9997, eventType=connect_fail, publisher=Tcpout, sourcePort=8089, statusee=TCPOutputProcessor
I ran the tcpdump command and the communication showed was between a virtual server on this Linux server and the indexer. The Linux server itself doesn't show up.
At this point, I am thinking of uninstalling the UF completely and reinstall after this server is upgraded which is supposed to be this year.