Installation

What about the disabled alerts after upgrading to 7.2?

snallam123
Path Finder

https://docs.splunk.com/Documentation/Splunk/7.2.5/Installation/AboutupgradingREADTHISFIRST

says disabled lookups will no longer be available after upgrade. Is it only lookups or everthing disabled.

We don't want any disabled alerts after the upgrade. Is there any way to remove all disabled alerts if we still get after upgrade?

Thanks.

Labels (1)
0 Karma

sloshburch
Ultra Champion

I believe you are asking about The use of disabled lookups in searches or other lookups is no longer allowed. My understanding of this is that if you have any saved searches or alerts that use lookups that are now disabled, those searches will throw an error saying as much. Consider this like a security fix because if a lookup is disabled nothing should still be using it.

Does that clarify?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...