Can you work with Support to get the older version? Also, what type of Splunk instance are you doing this on? Is it a UF, HF, Search Head, Indexer, etc? I think that might help you approach this. ...
See more...
Can you work with Support to get the older version? Also, what type of Splunk instance are you doing this on? Is it a UF, HF, Search Head, Indexer, etc? I think that might help you approach this. Based on the docs it sounds like losing some index configurations are part of the breaking changes. For example, if this was an Indexer you're upgrading and relying on the indexes.conf in the Windows app to define that index, then you'll need to move those configurations into another indexes.conf within your deployment. A similar situation exists for configurations included within authorize.conf for that older version. BUT, if this is just a UF, then some of this might be a moot point because UF's don't care about the indexes.conf configurations. You would probably have less concerns about doing this on a UF versus a Splunk instance that is part of the core infrastructure versus an edge agent.