Knowledge Management script throws Exec format error


I'm running Splunk Enterprise 6.4.1 on a Centos 7 machine. I need to backfill my summary index. I am running the following command on the searchhead :

./splunk cmd -app br -name br_volume_summary -et -1d@d -lt now -dedup true -nolocal true -auth admin: -owner ldc

The saved search is owned by ldc and has permission set to app with read/write to admin. The error I get is:

couldn't run "/opt/splunk/bin/": Exec format error

I thought maybe my aruments were invalid, so I tried to run with no arguments and got the same error. Any thoughts as to what it could be?

0 Karma


the same issue here

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!