Hi,
what's the correct way to upgrade the Lookup Editor app without loosing lookups?
Should I replace the current lookup_editor folder with the new one and then launch the command
$SPLUNK_HOME$/bin/splunk apply shcluster-bundle -target http://<SHcaptain>:<port> -preserve-lookups true ?
Or maybe I can just replace some of its folders or files? Is there something I need to keep or do in order not to loose old lookups?
Thank you in advance for any help.
Hi @Marco-IT,
having a Search Head Cluster, you have to upload the updated version of the lookup editor and then run the command you shared.
In details, it's important the option "-preserve-lookups true" to avoid to loose old lookups. as describet at https://docs.splunk.com/Documentation/Splunk/9.0.4/DistSearch/PropagateSHCconfigurationchanges#Prese...
Ciao.
Giuseppe
Hi @Marco-IT,
having a Search Head Cluster, you have to upload the updated version of the lookup editor and then run the command you shared.
In details, it's important the option "-preserve-lookups true" to avoid to loose old lookups. as describet at https://docs.splunk.com/Documentation/Splunk/9.0.4/DistSearch/PropagateSHCconfigurationchanges#Prese...
Ciao.
Giuseppe