Thanks!!
Another question I have about upgrade is:
We have Splunk enterprise 6.2 installed on Linux server. During installation, it was installed with user "splunk". Further, while starting splunk server, it was done using user "root",
Directory and files under $Splunk_home$ eg. bin, lib etc are created with "splunk" user has permission of 755.
Now, DB files under directory and sub-directory $Splunk_home$/var/lib/splunk are created with "root" user and has permission of 755.
I am not sure what is the best user to use to do the upgrade to 6.5.2 because both "root" and "splunk" user will face issue while writing on the files as there is a mixture.
Is there any solution you can suggest on this?
... View more