All Apps and Add-ons

How to upgrade lookup dditor without loosing lookups?

Marco-IT
Path Finder

Hi,

what's the correct way to upgrade the Lookup Editor app without loosing lookups?

Should I replace the current lookup_editor folder with the new one and then launch the command
$SPLUNK_HOME$/bin/splunk apply shcluster-bundle -target http://<SHcaptain>:<port> -preserve-lookups true ?
Or maybe I can just replace some of its folders or files? Is there something I need to keep or do in order not to loose old lookups?

Thank you in advance for any help.

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Marco-IT,

having a Search Head Cluster, you have to upload the updated version of the lookup editor and then run the command you shared.

In details, it's important the option "-preserve-lookups true" to avoid to loose old lookups. as describet at https://docs.splunk.com/Documentation/Splunk/9.0.4/DistSearch/PropagateSHCconfigurationchanges#Prese...

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Marco-IT,

having a Search Head Cluster, you have to upload the updated version of the lookup editor and then run the command you shared.

In details, it's important the option "-preserve-lookups true" to avoid to loose old lookups. as describet at https://docs.splunk.com/Documentation/Splunk/9.0.4/DistSearch/PropagateSHCconfigurationchanges#Prese...

Ciao.

Giuseppe

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...

SplunkTrust | 2024 SplunkTrust Application Period is Open!

It's that time again, folks! That's right, the application/nomination period for the 2024 SplunkTrust is ...