Knowledge Management script throws Exec format error


I'm running Splunk Enterprise 6.4.1 on a Centos 7 machine. I need to backfill my summary index. I am running the following command on the searchhead :

./splunk cmd -app br -name br_volume_summary -et -1d@d -lt now -dedup true -nolocal true -auth admin: -owner ldc

The saved search is owned by ldc and has permission set to app with read/write to admin. The error I get is:

couldn't run "/opt/splunk/bin/": Exec format error

I thought maybe my aruments were invalid, so I tried to run with no arguments and got the same error. Any thoughts as to what it could be?

0 Karma


the same issue here

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...