Quantcast
Channel: Questions in topic: "upgrade"
Viewing all articles
Browse latest Browse all 457

After upgrade from 6.2 to 6.3.0 data takes longer to be searchable or data stops "coming in at all"

$
0
0
Hi all, I have upgraded from 6.2 to 6.3.0 and now I am finding that data is appearing much later in searches. Indeed, sometimes no new data from several sources is not found at all in which cases restarting Splunk seems to be necessary to start fetching data again. This was not so with 6.2 installation. Ours is a small Splunk installation where "everything Splunk" runs on a Windows 2008R2 virtual machine. The cpu is not busy at all; it was working "much harder" with the previous version :-) We are retrieving data from about 100 "files & directories" and some apps almost all of which I have disabled. I am at loss as to where to start looking. I had a problem with kvstore which was resolved by running *D:\programs\splunk\bin\splunk.exe createssl server-cert -d . -n server* in *.\etc\auth*. Thanks to rbal_splunk: [link text][1] [1]: https://answers.splunk.com/users/177869/rbal_splunk.html?utm_source=answers&utm_medium=email&utm_term=%20rbal%20[Splunk]&utm_content=&utm_campaign=mention I have also disabled the *deployment monitor*. Any help is very much appreciated. Regards, Bård Tørustad

Viewing all articles
Browse latest Browse all 457

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>