Installation

Splunk ITSI upgrade

medavenu
Engager

Hello Team ,

 

We have a Splunk ITSI version running on 4.7.1 in Splunk Production and the plan is to upgrade to Splunk 4.9.1 in QA and DEV first followed by Splunk Production and I have upgraded to new version 4.9.1 in DEV ,when i am trying to restore the prod and setup in QA restore job is failing so that I can perform the complete Upgrade with KPI and Entity.

 

I even tried reverting the older version(4.7.1) and tried to restore the configurations in QA but still job is failing where as the backup was working fine so need your suggestions.

 

 

 

 

 

 

 

0 Karma

medavenu
Engager

These are the errors :

 

2021-11-09 13:49:15,413-0500 process:83173 thread:MainThread ERROR [itsi.controllers.itoa_rest_interface_provider] [__init__:1413] [exception] Restore failed, [[app/itsi/search?q=search%20index%3D%20_internal%20%20source%3D*itsi*%20migration&display.page.search.mode=smart&dispatch.sample_ratio=1&workload_pool=&earliest=-24h%40h&latest=now|check the related log]]. Traceback (most recent call last): File "/opt/splunk/etc/apps/SA-ITOA/lib/itsi/backup_restore/itsi_backup_restore_utils.py", line 678, in run worker.execute() File "/opt/splunk/etc/apps/SA-ITOA/lib/itsi/upgrade/kvstore_backup_restore.py", line 1172, in execute self.restore() File "/opt/splunk/etc/apps/SA-ITOA/lib/itsi/upgrade/kvstore_backup_restore.py", line 1148, in restore raise e File "/opt/splunk/etc/apps/SA-ITOA/lib/itsi/upgrade/kvstore_backup_restore.py", line 1140, in restore self.restore_from_folder() File "/opt/splunk/etc/apps/SA-ITOA/lib/itsi/upgrade/kvstore_backup_restore.py", line 978, in restore_from_folder raise Exception(failure_msg) Exception: Restore failed, [[app/itsi/search?q=search%20index%3D%20_internal%20%20source%3D*itsi*%20migration&display.page.search.mode=smart&dispatch.sample_ratio=1&workload_pool=&earliest=-24h%40h&latest=now|check the related log]].

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...