Splunk Enterprise

Upgrade from 9.1.3 to 9.2.2

dude49
Explorer

I did a recent upgrade of Splunk, but now notice my clients are not phoning in for some reason. This is my first upgrade in production environment, any help troubleshooting would be great. I still see my client configs on the backend but not sure why they are not reporting on the GUI. 

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

there have been major update how DS is working on 9.2. There are several threads in community where this is discussed. But basically these describe change and how to fix it.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

there have been major update how DS is working on 9.2. There are several threads in community where this is discussed. But basically these describe change and how to fix it.

r. Ismo

dude49
Explorer

Thanks this fixed the issue, added the stanza [indexAndForward] and they all popped right backup after the restart. Beautiful!!!! 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...