Installation

What happens if you run the 4.1 installer on a windows system that has an incomplete 4.1.1 installation?

muebel
SplunkTrust
SplunkTrust

I installed 4.1.1 this morning and have been unable to complete the installation or start Splunk. What kind of nastiness could occur if I ran the 4.1 installer in the hope of getting Splunk running again within the next few hours.

A good answer to this would also be an explanation of Splunk and "Downgrading" in general.

0 Karma
1 Solution

Mick
Splunk Employee
Splunk Employee

Between version 4.0.x and 4.1 Splunk underwent some major changes in both functionality and features. To make the new stuff work, a migration script has to be run on certain files to ensure that they are in the correct format/version for the changes to work. If you went from 4.0.10 to 4.1.1 and wanted to go back to 4.0.10, I'd say you would be in for a rough ride, unless you have a backup from your earlier instance.

Going from 4.1.1 back to 4.1 should prove less tricky, but there's no guarantee that it will solve your problem. In fact, it's more likely that the same problem will persist, and you could also possibly suffer from the issues that were fixed in the 4.1.1 build.

My advice would be to hold tight and contact your Support rep directly. It's likely that there's a small migration issue that can be fixed pretty quickly.

View solution in original post

Mick
Splunk Employee
Splunk Employee

Between version 4.0.x and 4.1 Splunk underwent some major changes in both functionality and features. To make the new stuff work, a migration script has to be run on certain files to ensure that they are in the correct format/version for the changes to work. If you went from 4.0.10 to 4.1.1 and wanted to go back to 4.0.10, I'd say you would be in for a rough ride, unless you have a backup from your earlier instance.

Going from 4.1.1 back to 4.1 should prove less tricky, but there's no guarantee that it will solve your problem. In fact, it's more likely that the same problem will persist, and you could also possibly suffer from the issues that were fixed in the 4.1.1 build.

My advice would be to hold tight and contact your Support rep directly. It's likely that there's a small migration issue that can be fixed pretty quickly.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...