All Apps and Add-ons

How to upgrade lookup dditor without loosing lookups?

Marco-IT
Path Finder

Hi,

what's the correct way to upgrade the Lookup Editor app without loosing lookups?

Should I replace the current lookup_editor folder with the new one and then launch the command
$SPLUNK_HOME$/bin/splunk apply shcluster-bundle -target http://<SHcaptain>:<port> -preserve-lookups true ?
Or maybe I can just replace some of its folders or files? Is there something I need to keep or do in order not to loose old lookups?

Thank you in advance for any help.

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Marco-IT,

having a Search Head Cluster, you have to upload the updated version of the lookup editor and then run the command you shared.

In details, it's important the option "-preserve-lookups true" to avoid to loose old lookups. as describet at https://docs.splunk.com/Documentation/Splunk/9.0.4/DistSearch/PropagateSHCconfigurationchanges#Prese...

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Marco-IT,

having a Search Head Cluster, you have to upload the updated version of the lookup editor and then run the command you shared.

In details, it's important the option "-preserve-lookups true" to avoid to loose old lookups. as describet at https://docs.splunk.com/Documentation/Splunk/9.0.4/DistSearch/PropagateSHCconfigurationchanges#Prese...

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...