I have splunk version 4.0.11, build 79031 on ubuntu 9.10, installed with "dpkg -i splunk-4.0.11-79031-linux-2.6-amd64.deb"
i upgraded it with "dpkg -Gi /usr/local/src/splunk-4.1.5-85165-linux-2.6-amd64.deb"
when I run "/opt/splunk/bin/splunk start" it fails, complaining with:
Perform migration and upgrade without previewing configuration changes? [y/n] y
-- Migration information is being logged to '/opt/splunk/var/log/splunk/migration.log.2010-09-24.10-35-44' --
Migrating to:
VERSION=4.1.5 BUILD=85165 PRODUCT=splunk PLATFORM=Linux-x86_64
Copying '/opt/splunk/etc/myinstall/splunkd.xml' to '/opt/splunk/etc/myinstall/splunkd.xml-migrate.bak'.
Checking saved search compatibility...
Handling deprecated files...
Checking script configuration... Copying '/opt/splunk/etc/system/local/indexes.conf' to '/opt/splunk/etc/system/local/indexes.conf.old'. Will migrate Windows scripted inputs. Migrating file /opt/splunk/etc/system/local/inputs.conf : Nothing to migrate here Migrating file /opt/splunk/etc/apps/search/local/inputs.conf : Nothing to migrate here Migrating file /opt/splunk/etc/apps/launcher/local/inputs.conf : Nothing to migrate here Migrating file /opt/splunk/etc/apps/windows/local/inputs.conf : Nothing to migrate here Migration of Windows scripted inputs completed. Copying '/opt/splunk/etc/myinstall/splunkd.xml.cfg-default' to '/opt/splunk/etc/myinstall/splunkd.xml'. Deleting '/opt/splunk/etc/apps/search/default/data/ui/manager/admin_field_values.xml'. Deleting '/opt/splunk/etc/system/local/field_actions.conf'. Moving '/opt/splunk/share/splunk/search_mrsparkle/modules' to '/opt/splunk/share/splunk/search_mrsparkle/modules.old.20100924-103538'. Moving '/opt/splunk/share/splunk/search_mrsparkle/modules.new' to '/opt/splunk/share/splunk/search_mrsparkle/modules'. Copying '/opt/splunk/etc/passwd' to '/opt/splunk/etc/passwd-formatchange.bak'.
Splunk will convert '/opt/splunk/etc/passwd' to a more secure format. The existing password file has been backed up at '/opt/splunk/etc/passwd-formatchange.bak'. This backup still contains weak passwords, and exists only to preserve the ability to downgrade to versions 4.1.3 and below. Please consider removing or archiving this backup, to increase the security of your users' passwords.
LDAP was determined to be pre-4.1: Backing up etc/passwd file to etc/passwd.bak Moving '/opt/splunk/etc/passwd' to '/opt/splunk/etc/passwd.bak'. App state in '/opt/splunk/etc/apps/PCI/default/MANIFEST' is not declared enabled or disabled, we default to enabled. Note: The app 'PCI' has both 3.x style MANIFEST files and 4.x style app.conf files. You may wish to review this app's state in manager to ensure it is enabled or disabled in accordance with your desires.
App state in '/opt/splunk/etc/apps/windows/default/MANIFEST' is not declared enabled or disabled, we default to enabled. Note: The app 'windows' has both 3.x style MANIFEST files and 4.x style app.conf files. You may wish to review this app's state in manager to ensure it is enabled or disabled in accordance with your desires.
Deleting '/opt/splunk/bin/listtails'. Deleting '/opt/splunk/etc/apps/search/default/data/ui/manager/data_extractions.xml'. Checking databases... ERROR :: 'homePath'
An error occurred: Could not validate indexes, will not continue (returned 1). root@splunk:/opt/splunk/bin#
Probably very similar if not the same as: http://answers.splunk.com/questions/4005/error-homepath-what-does-this-mean