【已解决】Splunk ES 升级后报警:that had previously been imported are not exporting configurations globally

1: 背景

  升级Splunk ES console alert后报警:

Health Check: One or more apps ("ABC,DEF") that had previously been imported are not exporting configurations globally to system. Configuration objects not exported to system will be unavailable in Enterprise Security.

2: 原因:

It seems that the those TA may not be shared globally or ES does not have access to read it. Could you check for those TA apps' permission under 'managed app', if they are shared globally, do check the add-on's local.meta file if there is "export = system" in it. You may follow the the section 

你可能感兴趣的:(splunk,splunk,ES,upgrade)