Roll back an upgrade of Splunk IT Essentials Work
If your upgrade to a new version of IT Essentials Work (ITE Work) fails, you can restore it to the previous state using the backup/restore functionality in either ITE Work or Splunk Enterprise.
Two types of backups are automatically taken before an ITE Work upgrade begins:
- A JSON-formatted ITE Work backup of the search head which is stored in $SPLUNK_HOME/etc/apps/SA-ITOA/lib. You can restore this backup using ITE Work's backup/restore functionality.
- A KV store backup taken by the KV store REST endpoint. The backup is stored in $SPLUNK_HOME/var/lib/splunk/kvstorebackup/. If you use the KV store backup, you also need to manually restore your local configuration files.
You can safely roll back your ITE Work upgrade using either of these methods.
Roll back an upgrade using the ITE Work backup
- Download and install the previous version of ITE Work that you upgraded from. You can find all past versions of ITE Work on Splunkbase.
- Restore the ITE Work backup from $SPLUNK_HOME/etc/apps/SA-ITOA/lib. For instructions, see Restore a full or partial backup of ITSI.
Roll back an upgrade using the Splunk Enterprise KV store backup
- Download and install the previous version of ITSI that you upgraded from. You can find all past versions of ITSI on Splunkbase.
- Restore the KV store backup from $SPLUNK_HOME/var/lib/splunk/kvstorebackup to the KV store directory through the kvstore/backup/restore endpoint.
- Manually restore your local configuration files stored in $SPLUNK_HOME/etc/apps/SA-ITOA/lib/backup_xxx/itsi_local.zip and $SPLUNK_HOME/etc/apps/SA-ITOA/lib/backup_xxx/itoa_local.zip. To restore the files, manually untar them into the following locations:
Backup location Untarred location $SPLUNK_HOME/etc/apps/SA-ITOA/lib/backup_xxx/itsi_local.zip $SPLUNK_HOME/etc/apps/itsi/local $SPLUNK_HOME/etc/apps/SA-ITOA/lib/backup_xxx/itoa_local.zip $SPLUNK_HOME/etc/apps/SA-ITOA/local
Upgrade Splunk IT Essentials Work on a search-head cluster
Uninstall ITE Work
This documentation applies to the following versions of Splunk® IT Essentials Work: 4.12.0 Cloud only