Installation

Manager Icons "Generic" After Upgrade to 4.3.4 (from 4.2.3)

I_am_Jeff
Communicator

Last night I upgraded our Splunk "cluster" from 4.2.3 to 4.3.4. We have two pooled search heads. As the upgrade doc says, take the search heads out of the pool before you upgrade. After upgrading them all, put them back in the pool.

Search heads are up. Splunk sure appears to be working normally. But the icons on the Splunk > Manager page are all generic gear icons. My indexers show the new ones. I have two questions.

  1. How do I get the new icons visible on my search heads?
  2. Are other items in the pool area is should worry about?

For example, the web page source generated from the search head says:

[a class="spl-manager-icon-default" href="/en-US/manager/system/licensing"]Licensing[/a]

The indexer says:
[a class="spl-manager-icon-licensing" href="/en-US/manager/system/licensing"]Licensing[/a]

(I've changed the angle brackets <> to square brackets [] so the HTML doesn't render.)

1 Solution

I_am_Jeff
Communicator

I flubbed this step in The Distributed Deployment Manual, Upgrade your distributed environment

After you upgrade the search head, place the confirmed working apps into

the $SPLUNK_HOME/etc/apps directory of the search head.

$SPLUNK_HOME is the pool area. Thanks to support for walking me through this.

(for those that want to see the link)
http://docs.splunk.com/Documentation/Splunk/4.3.4/Deploy/Upgradeyourdistributedenvironment

View solution in original post

I_am_Jeff
Communicator

I flubbed this step in The Distributed Deployment Manual, Upgrade your distributed environment

After you upgrade the search head, place the confirmed working apps into

the $SPLUNK_HOME/etc/apps directory of the search head.

$SPLUNK_HOME is the pool area. Thanks to support for walking me through this.

(for those that want to see the link)
http://docs.splunk.com/Documentation/Splunk/4.3.4/Deploy/Upgradeyourdistributedenvironment

fk319
Builder

Another thing that we noticed was that the window for edit code has only three lines, and no color.

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...