Splunk Enterprise

Upgrading app lost kvstore objects (TenableAppForS

donelliot
Path Finder

I thought I was following OK practice as these were customisations to collections.conf and transforms.conf and savedsearches.conf in the local directory

But it appears the app owner just got rid of them when I upgraded to 5.0.0 to 5.1.0

Working to recover the situation and have pinged the developer. The data should be recreated

Was it my fault by adding stanzas to a commercial app ? or should I have been protected if I stuck to local copies ?

 

 

Labels (1)
Tags (1)
0 Karma

donelliot
Path Finder

As before I just clicked on upgrade in the management of apps screen and it seems to have emptied the local directory ! restoring from a backup

0 Karma

donelliot
Path Finder

I got  an all-in one setup, and just download the app without pre-testing - my bad

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Ok. But how did you update them? Using the "apps" screen in splunk webui? By downloading them manually and installing them from cli?

0 Karma

donelliot
Path Finder

I'm fairly sure by clicking on the update hint  from the manaagement screen /en-US/manager/launcher/apps/local

0 Karma

PickleRick
SplunkTrust
SplunkTrust

If you had your definitions in app/local directory, it should have been retained across upgrades. The app should overwrite the app/default directory (and therefore you should never directly edit files there) but your local files shouldn't be touched.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What is your environment? Do you use all-in-one setup or do you have search-head cluster? How do you deploy apps? How did you upgrade the app?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...