Splunk Enterprise Security
Highlighted

Fail on start splunk after the upgrade of Splunk Enterprise Security from v4.7.0 to 5.3.1.

After upgrade to Splunk Enterprise Security v 5.3.1, fail on startup with the following error:

[root@splunk02 bin]# ./splunk start

Splunk> Another one.

Checking prerequisites...
Checking http port [8000]: open
Checking mgmt port [8089]: open
Checking appserver port [127.0.0.1:8065]: open
Checking kvstore port [8191]: open
Checking configuration... Done.
Checking critical directories... Done
Checking indexes...
Problem parsing indexes.conf: Cannot load IndexConfig: stanza=perfmon Required parameter=homePath not configured
Validating databases (splunkd validatedb) failed with code '1'. If you cannot resolve the issue(s) above after consulting documentation, please file a case online at http://www.splunk.com/page/submit_issue

0 Karma
Highlighted

Re: Fail on start splunk after the upgrade of Splunk Enterprise Security from v4.7.0 to 5.3.1.

as far as I know perfmon is a process associated with Windows OS, however our splunk was installed on linux.

0 Karma