Splunk Search

Splunk upgrade from 5.0.9 to 6.1.2: Why can't I search?

rmorlen
Splunk Employee
Splunk Employee

Upgraded from Splunk 5.0.9 to 6.1.2. Can't search. Seeing the following message: "In handler 'jobs': Cannot perform action "POST" without a target name to act on.".

Anyone have any suggestions where I can look for a fix?

Tags (2)

andrewfoglesong
Explorer

You can run the splunk btool --debug tool. I had several "No spec file for: ... .conf" entries after moving from 5.0.4 to 6.2.3. Then I remembered I had some sandboxing app with copies of ALL the default configuration files in it. I removed the app, restarted Splunk, and everything appeared to work after that.

My guess is that there are some incompatibilities between the different configuration stanzas and syntax of 5/6 and that while the migration will overwrite the conflicts in the /default paths, it won't touch conflicting settings if they are somewhere else (i.e., /apps). I thought Splunk 5 actually included some deprecated setting stanzas from 4 to avoid this but it doesn't seem to be 100% true going from 5 to 6.

0 Karma

rmorlen
Splunk Employee
Splunk Employee

Thanks. Yes I filed a case with support.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The first step towards debugging would be to look into the _internal index at the time of that error for further info.

Did you file a case with support?

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...