Splunk Search

After upgrading from Splunk 6.1.1 to 6.19, why am I getting "appear to be running outdated version of search app..." on our search head?



I just upgraded from 6.1.1 to 6.1.9, and now, in the search head, a message is appearing, telling me that the search app appears to be outdated. "Running an outdated version of search app...". We are running search head pooling. Do I need to move the local etc/apps/ and move them to our NAS?

0 Karma


If you have your apps pooled you must copy the pooled apps to a local apps folder and then upgrade Splunk. It sounds like you upgraded Splunk without that step.

0 Karma
Get Updates on the Splunk Community!

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...