Upgrade Issues - Splunk Enterprise Troubleshooting Use Case - 40

07.07.24 01:00 PM - By Murugan

Upgrade Issues 

Issue:
- After upgrading to Splunk UF to v9.1.3 version, data flow is happening, but Windows instance is exhausting the CPU.
Root Cause:
- Version 9.1 and above are installed by default with a VSA (virtual service account), which can cause problems with certain paths and resources.
Solution:
- Enable the UF to run with “Local System account”. While upgrading the UF, do it from Command Line with the USE_LOCAL_SYSTEM option, which can be set to "1" to install as the Local System

Murugan