Splunk Search

Splunk Enterprise AMI and Splunk aws Quickstart

console
New Member

I have a CloudFormation stack for a splunk setup that I created using the AWS Splunk Quickstart from https://aws.amazon.com/quickstart/architecture/splunk-enterprise/. The quickstart uses a old version of the Splunk enterprise AMI. So i changed the AMI to the latest version (splunk_AMI_7.3.0_2019-06-03_05_00_24-7b65de6c-5006-4ca2-bd75-fdba95ae5d9d-ami-06388b0c8952b37fa.4 (ami-019ccf2f6bb16aecd) for eu-central-1)

But the new AMI does install the splunk files and data after launch using a ansible playbook, while the old ami did have everything setup and ready to go at launch.

This causes Problems with the UserData scripts that are used in the quickstart to configure the cluster. They fail because the files are missing.

mv $SPLUNK_HOME/etc/passwd $SPLUNK_HOME/etc/passwd.bak
mv: cannot stat ‘/opt/splunk/etc/passwd’: No such file or directory

You can reproduce this error by taking the quickstart cloudformation template, and changing the AMI to the latest Splunk AMI in your region.

How can I get the setup script from the Quickstart to work on the latest Splunk AMI?

Tags (1)
0 Karma

msilvero
New Member

Hi,

Having the same issue, is anyone have some fix?

Thx

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...