We went through an upgrade to 6.5.1 and the upgrade touched SPLUNK_HOME/etc/system/local on the indexers. Should it happen? We see indexes.conf with a new timestamp.
SPLUNK_HOME/etc/system/local
indexes.conf
Hi dddillic,
We had that happened when doing a Splunk upgrade from 6.4.3 to 6.5.0 on SBOX 1.4 - which was confirmed as a SBOX bug....
Hope this helps ...
cheers, MuS
View solution in original post