Splunk ITSI

Splunk ITSI Services,KPI base searches,Corr search , Aggregation policy all missing after setting up SH and Indexer Cluster

prafullwt
New Member

Hi All,
Recently i upgraded my standalone env to SH and Indexer cluster one major thing i notice is all my previous works like Services,entities,correlation search,notable event aggregation policies are missing.
Basically it's set back to default.

Where and how can i restore my previous work ?

0 Karma

szhou_splunk
Splunk Employee
Splunk Employee

Hi, @prafullwt , which version did you upgrade from and to which version?
Maybe it is being migrated. Did you see any errors with the following search?
index=_internal sourcetype="itsi_internal_log" source="*itsi_upgrade*"

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Incident Response: Reduce Incident Recurrence with Automated Ticket Creation

Culture extends beyond work experience and coffee roast preferences on software engineering teams. Team ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 2)

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...