Installation

Upgraded to 4.3.3 (from 4.2.2). Lost Saved Search owners

Sqig
Path Finder

Hi. We just upgraded from 4.2.2 to 4.3.3.

We are using search head pooling, so we followed the specific instructions for dealing with that situation (ie, unpool, upgrade each head, repool).

Now, it seems that Views and Saved Searches by some of our users are showing up as having no owner.

I checked and it looks to me like the user's directory exists in $SHARED/etc/users and (as you might expect) not in $SPLUNK_HOME/etc/users

Has anyone else run into this? I did make a backup of everything before the upgrade, so if the upgrade clobbered some critical files I'm not aware of, I could replace them, I just don't even know where to start!

Tags (3)
0 Karma
1 Solution

rmorlen
Splunk Employee
Splunk Employee

We run Splunk pooled. Typically for an upgrade I do the following:

Stop Splunk

Unpool

Backup the pooled etc/users and etc/apps

Copy etc/users to local $SPLUNK_HOME/etc/users

Copy etc/apps to local $SPLUNK_HOME/etc/apps

Upgrade Splunk

Start Splunk

Stop Splunk

Copy $SPLUNK_HOME/etc/users back the pooled location

Copy $SPLUNK_HOME/etc/apps back to the pooled location

Enable Pooling

Start Splunk

I only do the copy (both directions) for one server since it is pooled.

View solution in original post

0 Karma

rmorlen
Splunk Employee
Splunk Employee

We run Splunk pooled. Typically for an upgrade I do the following:

Stop Splunk

Unpool

Backup the pooled etc/users and etc/apps

Copy etc/users to local $SPLUNK_HOME/etc/users

Copy etc/apps to local $SPLUNK_HOME/etc/apps

Upgrade Splunk

Start Splunk

Stop Splunk

Copy $SPLUNK_HOME/etc/users back the pooled location

Copy $SPLUNK_HOME/etc/apps back to the pooled location

Enable Pooling

Start Splunk

I only do the copy (both directions) for one server since it is pooled.

0 Karma

Sqig
Path Finder

Thanks. I thought to copy pooled/etc/apps back pre-upgrade but not pooled/etc/users. Looks like i have to roll back on one server and re-upgrade in order for all the apps to see their rightful owners.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...