<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrade ES in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758126#M23830</link>
    <description>&lt;P&gt;You can find bits and pieces about kvstore in Splunk docs. It's "just" a mongodb instance so much of mongodb experience applies here as well.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Feb 2026 22:27:13 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2026-02-06T22:27:13Z</dc:date>
    <item>
      <title>Upgrade ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758024#M23810</link>
      <description>&lt;P&gt;I would like to upgrade from 9.0.0 to 10.2.0 while keeping the same license. The license is&amp;nbsp;Splunk Enterprise - No Enforcement. Also, my 9.0.0 is not working correctly. It states that I can't update the KV store, and I also get this error message: Could not load lookup=LOOKUP-splunk_security_essentials.&lt;SPAN&gt;&amp;nbsp;Will an upgrade help with that?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 15:16:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758024#M23810</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2026-02-05T15:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758025#M23811</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264375"&gt;@jovnice&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firstly, I dont think the upgrade should affect your license, so this shouldnt be an issue.&lt;/P&gt;&lt;P&gt;Regarding the KV Store update, if it was me I would focus on fixing this first before upgrading to 10.2.0.&lt;/P&gt;&lt;P&gt;You will need to upgrade from 9.0.x to 9.2.x and then 9.4.x before upgrading to 10.2.x (See&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.2/upgrade-or-migrate-splunk-enterprise/how-to-upgrade-splunk-enterprise" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.2/upgrade-or-migrate-splunk-enterprise/how-to-upgrade-splunk-enterprise&lt;/A&gt;) - This will ensure any iterative upgrade requirements like KV Store upgrades are met, but like I said - Start with a working system!&lt;/P&gt;&lt;P&gt;The splunk_security_essentials lookup could be related to the KV Store issue, Im not 100% where this comes from so I would fix the KV Store issue first.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 16:02:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758025#M23811</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-02-05T16:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758027#M23812</link>
      <description>&lt;P class="lia-align-left"&gt;Thank you for the information. Is there any information on the KV store upgrade, or why it is not working?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 16:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758027#M23812</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2026-02-05T16:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758037#M23817</link>
      <description>&lt;P&gt;1. You're asking about Splunk Enterprise, not ES (which is Enterprise Security).&lt;/P&gt;&lt;P&gt;2. Well, without more info we can't know why your upgrade doesn't work. Maybe you skipped some versions before, maybe your kvstore database is corrupted. That's what the logs are for - see what's in them.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 21:08:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758037#M23817</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-02-05T21:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758078#M23823</link>
      <description>&lt;P&gt;Yes, I mean SE (&lt;SPAN&gt;Splunk Enterprise).&amp;nbsp; Thanks for responding.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I haven't tried the upgrade yet because I wasn't sure whether it would fix the kvstore database issue. I want to update once I know if it's working or if there is any documentation on the KVStore database.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 14:04:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758078#M23823</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2026-02-06T14:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758126#M23830</link>
      <description>&lt;P&gt;You can find bits and pieces about kvstore in Splunk docs. It's "just" a mongodb instance so much of mongodb experience applies here as well.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 22:27:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758126#M23830</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-02-06T22:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758140#M23834</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264375"&gt;@jovnice&lt;/a&gt;&amp;nbsp; Splunk Enterprise upgrade is not tied with your license, so you are good to proceed after fixing the issues in KV Store.&lt;BR /&gt;&lt;!-- StartFragment  --&gt;&lt;/P&gt;&lt;P&gt;For KV Store issues in Splunk, check for errors or warnings in&amp;nbsp;&lt;STRONG&gt;mongod.log &lt;/STRONG&gt;file.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Located under the path :&amp;nbsp;&lt;PRE&gt;$SPLUNK_HOME/var/lib/splunk/kvstore/mongo&lt;/PRE&gt;&lt;/LI&gt;&lt;!-- EndFragment  --&gt;&lt;/UL&gt;&lt;P&gt;I highly recommend you to collect these ERROR details and raise a Support case with Splunk before trying any remediation from your end since KV Store troubleshooting can be critical for the entire Splunk setup. Had few bad experiences in the past with KV store troubleshooting and eventually contacted Splunk Support to recover.&lt;BR /&gt;&lt;BR /&gt;For the Lookup error on Splunk Security Essentials, it&lt;!-- StartFragment  --&gt;&amp;nbsp;could be related to either a corrupted or missing lookup file or running an app version not aligned with your current Splunk version, which is 9.0.0.&lt;BR /&gt;&lt;BR /&gt;Hope this helps and happy to help if you have any further questions.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp;&lt;EM&gt;Marking the answer and giving Karma helps others find solutions faster!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Feb 2026 08:23:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758140#M23834</guid>
      <dc:creator>kknairr</dc:creator>
      <dc:date>2026-02-07T08:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758186#M23840</link>
      <description>&lt;P&gt;I've been looking there, but I didn't see the issue I'm having, so I can't troubleshoot.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 17:26:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758186#M23840</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2026-02-09T17:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758187#M23841</link>
      <description>&lt;P&gt;Thanks for your help. I will look into this further.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 17:44:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758187#M23841</guid>
      <dc:creator>jovnice</dc:creator>
      <dc:date>2026-02-09T17:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758356#M23870</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264375"&gt;@jovnice&lt;/a&gt;&amp;nbsp;Refer to my earlier response and let us know if that gives you direction.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Feb 2026 06:41:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upgrade-ES/m-p/758356#M23870</guid>
      <dc:creator>kknairr</dc:creator>
      <dc:date>2026-02-14T06:41:04Z</dc:date>
    </item>
  </channel>
</rss>

