Splunk Enterprise Security

What happens to ES, it's settings, configurations when Splunk Enterprise is upgraded to a new version like 8.2.2.1 ?

SamHTexas
Builder

We have Splunk Ent. (8.0) & ES.(6.4). What is a proper procedure to upgrade to Splunk Enterprise 8.2.2.1 to retain the settings & configurations we have done to ES (Enterprise Security)? What about Security Essentials we have installed. Any directions are much appreciated. Thanks a million.

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Depends of what you have already done with your installation. Since you ask many questions which should be covered by any reasonable basic splunk training and seem to not put any effort into finding answers on your own, we can imagine that your servers are not managed the way they should be.

So, if you fiddled with "default" directories of the built-in apps, upgrade will overwrite your changes. If you kept your configurations in "local", nothing bad should happen.

And app upgrade is a different thing than core splunk software upgrade.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...