I've got two splunk indexers that also act as our search heads. Search head pooling is configured on them and has been working fine. This morning I upgraded from 4.3.1 to 4.3.2. After the upgrade some of our saved searches are no longer showing up in the search app, but they are still in the /etc/apps/search/local/savedsearches.conf file.

A similar thing is happening with some of our field extracts, where some are showing up and some are not.

Any ideas?

Does running "splunk btool find-dangling" produce any output?

If so, running "splunk btool fix-dangling" might help.