Installation

Some saved searches disappeared after upgrade

jevenson
Path Finder

I've got two splunk indexers that also act as our search heads. Search head pooling is configured on them and has been working fine. This morning I upgraded from 4.3.1 to 4.3.2. After the upgrade some of our saved searches are no longer showing up in the search app, but they are still in the /etc/apps/search/local/savedsearches.conf file.

A similar thing is happening with some of our field extracts, where some are showing up and some are not.

Any ideas?

0 Karma

ewoo
Splunk Employee
Splunk Employee

Does running "splunk btool find-dangling" produce any output?

If so, running "splunk btool fix-dangling" might help.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...