Splunk Search

Splunk Enterprise AMI and Splunk aws Quickstart

console
New Member

I have a CloudFormation stack for a splunk setup that I created using the AWS Splunk Quickstart from https://aws.amazon.com/quickstart/architecture/splunk-enterprise/. The quickstart uses a old version of the Splunk enterprise AMI. So i changed the AMI to the latest version (splunk_AMI_7.3.0_2019-06-03_05_00_24-7b65de6c-5006-4ca2-bd75-fdba95ae5d9d-ami-06388b0c8952b37fa.4 (ami-019ccf2f6bb16aecd) for eu-central-1)

But the new AMI does install the splunk files and data after launch using a ansible playbook, while the old ami did have everything setup and ready to go at launch.

This causes Problems with the UserData scripts that are used in the quickstart to configure the cluster. They fail because the files are missing.

mv $SPLUNK_HOME/etc/passwd $SPLUNK_HOME/etc/passwd.bak
mv: cannot stat ‘/opt/splunk/etc/passwd’: No such file or directory

You can reproduce this error by taking the quickstart cloudformation template, and changing the AMI to the latest Splunk AMI in your region.

How can I get the setup script from the Quickstart to work on the latest Splunk AMI?

Tags (1)
0 Karma

msilvero
New Member

Hi,

Having the same issue, is anyone have some fix?

Thx

0 Karma
Get Updates on the Splunk Community!

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...