Does anyone know if there is a particular file Splunk looks for to determine if the Splunk version has changed?
Background. Using Google Slack project (wrapper around rsync or ssh) to update my forwarders.
Periodically, something is causing Splunk to think its version has changed and I get the license agreement prompt and upgrade confirmation prompt.
I can bypass the license agreement with --accept-license but have not found a way to bypass the upgrade confirmation (want force "y").
This causes a problem since we regularly restart our services through crontabs and Splunk fails to start when this situation arises.