Splunk Enterprise

Upgrading app lost kvstore objects (TenableAppForS

donelliot
Path Finder

I thought I was following OK practice as these were customisations to collections.conf and transforms.conf and savedsearches.conf in the local directory

But it appears the app owner just got rid of them when I upgraded to 5.0.0 to 5.1.0

Working to recover the situation and have pinged the developer. The data should be recreated

Was it my fault by adding stanzas to a commercial app ? or should I have been protected if I stuck to local copies ?

 

 

Labels (1)
Tags (1)
0 Karma

donelliot
Path Finder

As before I just clicked on upgrade in the management of apps screen and it seems to have emptied the local directory ! restoring from a backup

0 Karma

donelliot
Path Finder

I got  an all-in one setup, and just download the app without pre-testing - my bad

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Ok. But how did you update them? Using the "apps" screen in splunk webui? By downloading them manually and installing them from cli?

0 Karma

donelliot
Path Finder

I'm fairly sure by clicking on the update hint  from the manaagement screen /en-US/manager/launcher/apps/local

0 Karma

PickleRick
SplunkTrust
SplunkTrust

If you had your definitions in app/local directory, it should have been retained across upgrades. The app should overwrite the app/default directory (and therefore you should never directly edit files there) but your local files shouldn't be touched.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What is your environment? Do you use all-in-one setup or do you have search-head cluster? How do you deploy apps? How did you upgrade the app?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...