Hello!
I have recently upgraded my splunk enterprise servers from 9.1.2 to 9.2.1. I noticed the following web behaviors in deployment server ;
1. When searching for hostname, it takes a long time to load
2. Server class and app for (any) host is not reflecting correctly. This was crossed checked on CLI serverclass.conf
Wondering if anyone face this issue and if it is a GUI bug.
With the new version, there are a number of changes, have a look through this doc, in short, you need to ensure a number of new indexes are in place _ds* see the doc and there's another setting in the output.conf of the deployment server and add the new whitelist indexes to the UF's. Try these if it still fails log a support call.
https://docs.splunk.com/Documentation/Splunk/9.2.0/Updating/Upgradepre-9.2deploymentservers
Hello,
Thanks for your response. I have added the necessary configuration according to the article that you shared. But we are still facing this issue.
The UI loading is slow as well.
If you done that, then best course or action might be log a support ticket, as there could be another underlying issue.