Hello,
is there any recommandation to upgrade 2.7.0 to 3.3.3 on Splunk 7.1.4 (clustered SH)?
Should we just delete "lookup_editor" in /etc/shcluster on deployer, extract new version then deploy it?
We currently have an issue with lookup files being owned by "nobody" user on 2.7.0 version ( issue link text )
Thanks.
Solved, just needed to restart search heads, app update installed by deploying new untarred files from deployer.
Solved, just needed to restart search heads, app update installed by deploying new untarred files from deployer.