Installation

Upgraded to 4.3.3 (from 4.2.2). Lost Saved Search owners

Sqig
Path Finder

Hi. We just upgraded from 4.2.2 to 4.3.3.

We are using search head pooling, so we followed the specific instructions for dealing with that situation (ie, unpool, upgrade each head, repool).

Now, it seems that Views and Saved Searches by some of our users are showing up as having no owner.

I checked and it looks to me like the user's directory exists in $SHARED/etc/users and (as you might expect) not in $SPLUNK_HOME/etc/users

Has anyone else run into this? I did make a backup of everything before the upgrade, so if the upgrade clobbered some critical files I'm not aware of, I could replace them, I just don't even know where to start!

Tags (3)
0 Karma
1 Solution

rmorlen
Splunk Employee
Splunk Employee

We run Splunk pooled. Typically for an upgrade I do the following:

Stop Splunk

Unpool

Backup the pooled etc/users and etc/apps

Copy etc/users to local $SPLUNK_HOME/etc/users

Copy etc/apps to local $SPLUNK_HOME/etc/apps

Upgrade Splunk

Start Splunk

Stop Splunk

Copy $SPLUNK_HOME/etc/users back the pooled location

Copy $SPLUNK_HOME/etc/apps back to the pooled location

Enable Pooling

Start Splunk

I only do the copy (both directions) for one server since it is pooled.

View solution in original post

0 Karma

rmorlen
Splunk Employee
Splunk Employee

We run Splunk pooled. Typically for an upgrade I do the following:

Stop Splunk

Unpool

Backup the pooled etc/users and etc/apps

Copy etc/users to local $SPLUNK_HOME/etc/users

Copy etc/apps to local $SPLUNK_HOME/etc/apps

Upgrade Splunk

Start Splunk

Stop Splunk

Copy $SPLUNK_HOME/etc/users back the pooled location

Copy $SPLUNK_HOME/etc/apps back to the pooled location

Enable Pooling

Start Splunk

I only do the copy (both directions) for one server since it is pooled.

0 Karma

Sqig
Path Finder

Thanks. I thought to copy pooled/etc/apps back pre-upgrade but not pooled/etc/users. Looks like i have to roll back on one server and re-upgrade in order for all the apps to see their rightful owners.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...