Splunk Enterprise Security

Splunk ES Incident dashboard not working with Splunk Enterprise 7.1.2

teddyidc1101
Communicator

We upgraded our Splunk enterprise to 7.1.2 from 7.0 version in a SH that has Splunk ES version 4.7.2.
After the upgrade, we notice that Incident Review dashboard doesn't work as expected.
If we upgrade the Splunk ES, will this be fixed?
Also, if we plan on upgrading, should we do Splunk ES first them Splunk Enterprise? What will be the sequence for these upgrades?

Thanks!

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

Only version 5.1.x of Splunk ES is compatible with version 7.1.x of the Splunk platform. Because you have already upgraded Splunk Enterprise, upgrade Splunk ES. If you can't upgrade both at the same time, plan it out so that the version combinations of the products are compatible.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...