Hi Helpers - Below is my usecase where I am stuck with my ES upgrade.
My Splunk version recently upgraded from 7.2.7 to 8.1.3
Post the Splunk upgrade, Splunk ES views were throwing pop-up messages “Timelines could not be loaded”. Splunk ES was on 4.5.2 which was working fine on Splunk 7.2.7. Since it looked incompatible, we planned to upgrade it to 6.2.0. Below is the process followed.
It's on a SHC environment with 3 Search Heads
Bit confused with the documentation. Upgrade documentation didn't have essinstall action=upgrade part. But read about it in some blog. Am I supposed to run it or not?
When I followed the upgrade documentation, only SplunkEnterpriseSecuritySuite app folder got changed and the remaining SA-* and DA-* apps were unchanged.
But SA-* and DA-* got changed when I ran essinstall command followed by splunk restart.
All this is just on deployer. Haven't pushed any changes to search heads.
Has anyone recently did ES upgrade and can share me clear steps to be followed?
Raised a Splunk support case and they are advicing just to follow the upgrade doco which is fully not clear.
Thanks & Regards,