Splunk Search

How to ensure upgrade of saved search, which was modified by customer and is now in local folder while customer upgrades app?

MegSplunk
Path Finder

A customer installs version 1 of my app. Uses the Splunk Web UI to make changes to one of the saved searches. This search is now in the local folder. ($SplunkHome/etc/apps/MyApp/local). I release version 2 of my app. The customer upgrades the app. But the saved search residing in the local folder would not be updated (There would not be any local folder in my app). Other custom reports created by the customer are also present in the local folder.

One way to ensure that the saved search in local folder is upgraded is by deleting it from there. Is there any other way to achieve this?

Tags (1)
0 Karma

mhassan
Path Finder

This is true for the "upgrade" process (using RPM or gz files). It is not true if you are using deployment server to push new apps. The old directory (xyz-app directory) always get deleted and push from the deployment server.
I don't know of better way of doing this!

0 Karma

gfuente
Motivator

Thats exactly the purpose of those folders. The local one is used for customizations, and won´t be overrided by updates, therefore the default folder is used to deploy upgrades of the default app without overwritting customizations.

So the only way would be delete custom searches, or update them manually in the local folder

Regards

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...