I upgraded from Splunk 3.4.9 to 4.0.1 and then to 4.1.5 using localsystem as the account.
After I upgraded the second time the splunkd service was disabled.
I tried to reactivate after changing to a domain account (with the appropriate permissions).
The service is "marked for deletion" and will not allow me to change user accounts or start.
Where do I go from here? Do I need to start my upgrades all over again?
... View more