Splunk Enterprise

Error when upgrading Splunk Enterprise from 9.0. to 9.2.1

SahilGupta942
Loves-to-Learn

Hello Team,

I had followed steps mentioned in below page for migration to Splunk Enterprise version 9.2.1:

Upgrade to version 9.2 on UNIX - Splunk Documentation

I receive below error on running start command. Due to this error, I am unable to complete the migration on Splunk indexer machine.

SahilGupta942_0-1715670173143.png

Warning: cannot create "/data/splunk/index_data"
Creating: /data/splunk/index_data
ERROR while running renew-certs migration.

Labels (1)
0 Karma

swdngiti
New Member

i have the same situation when i try to migration my splunk from old server RHEL6.9 to new RHEL8.8

i did rsync complete and created user splunk as new server

ran rpm -i of same version to the new server and shows complete with zero error, however when i went to /opt/splunk/bin and ./splunk start it shows same error like you.

 

May i know any update of yours, did you fixed ?

0 Karma

deepakc
Builder

This looks like looks like filesystem permissions. 

The splunk paths are normally based on the splunk account user permissions 
example 
sudo chown -R splunk:splunk <YOUR DATA PATH>

Find out what account Splunk was running under. 

PickleRick
SplunkTrust
SplunkTrust

Or - if the permissions look right - a SELinux mislabeling issue.

Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...