All Apps and Add-ons

How to upgrade lookup dditor without loosing lookups?

Marco-IT
Path Finder

Hi,

what's the correct way to upgrade the Lookup Editor app without loosing lookups?

Should I replace the current lookup_editor folder with the new one and then launch the command
$SPLUNK_HOME$/bin/splunk apply shcluster-bundle -target http://<SHcaptain>:<port> -preserve-lookups true ?
Or maybe I can just replace some of its folders or files? Is there something I need to keep or do in order not to loose old lookups?

Thank you in advance for any help.

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Marco-IT,

having a Search Head Cluster, you have to upload the updated version of the lookup editor and then run the command you shared.

In details, it's important the option "-preserve-lookups true" to avoid to loose old lookups. as describet at https://docs.splunk.com/Documentation/Splunk/9.0.4/DistSearch/PropagateSHCconfigurationchanges#Prese...

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Marco-IT,

having a Search Head Cluster, you have to upload the updated version of the lookup editor and then run the command you shared.

In details, it's important the option "-preserve-lookups true" to avoid to loose old lookups. as describet at https://docs.splunk.com/Documentation/Splunk/9.0.4/DistSearch/PropagateSHCconfigurationchanges#Prese...

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out &gt;&gt; As our brave ...