Hello, I am having issues with my splunk universal fowarders. Problem: The Splunk Universal Forwarders are not upgrading from version 7.2.6 to Version 8 using the custom app I developed. However, The custom app is a replica of 7.2.6. I created a another app that has the exact same features as version 7.2.6. However, once it shuts down, it does not restart or upgrade the server. Here is the custom app. #!/bin/bash # set splunk path SPLUNK_HOME=/opt/splunkforwarder # set desired version NVER=8.2.2 # determine current version CVER=`cat $SPLUNK_HOME/etc/splunk.version | grep VERSION | cut -d= -f2` if [ "$NVER" != "$CVER" ] then echo "Upgrading Splunk to $NVER." $SPLUNK_HOME/bin/splunk stop tar -xvf $SPLUNK_HOME/etc/apps/splunk_upgrade_lin_v8/static/splunkforwarder-8.2.2-87344edfcdb4-Linux-x86_64.tgz -C /opt $SPLUNK_HOME/bin/splunk start --accept-license --answer-yes fi In the static folder, it has the splunkforwarder-8.2.2-87344edfcdb4-Linux-x86_64.tgz. In the bin directory, the script above is the upgrade.sh and the wrapper.sh I created points to this upgrade.sh In the local directory, this is what I have listed. [script://./bin/wrapper.sh] disabled = false interval = 3600 sourcetype = upgrade_linuxv8 Once again. This custom apps work completely fine with 7.2.6. Any version after that, splunk just stops once the app is assigned to the client, then the splunkforwarder shuts down and doesn't come back until I force remove the app (rm -rf) and restart splunk. Does Anyone has a work around with this?
... View more