Splunk Enterprise Security

Splunk ES Incident dashboard not working with Splunk Enterprise 7.1.2

teddyidc1101
Communicator

We upgraded our Splunk enterprise to 7.1.2 from 7.0 version in a SH that has Splunk ES version 4.7.2.
After the upgrade, we notice that Incident Review dashboard doesn't work as expected.
If we upgrade the Splunk ES, will this be fixed?
Also, if we plan on upgrading, should we do Splunk ES first them Splunk Enterprise? What will be the sequence for these upgrades?

Thanks!

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

Only version 5.1.x of Splunk ES is compatible with version 7.1.x of the Splunk platform. Because you have already upgraded Splunk Enterprise, upgrade Splunk ES. If you can't upgrade both at the same time, plan it out so that the version combinations of the products are compatible.

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...