We just upgraded to Splunk 5.0.5 and noticed that the indexers were periodically missing data. One of the first things I wanted to look at was our installed S.o.S app. When I brought it up and launched "Data Inputs Overview", I got a "Error in 'rex' command. Failed to initialize sed. Invalid option string: /g" message and nothing showing up in the graphs.
When I looked at splunk>Manager >> Apps, I saw the following;
Sideview Utils 1.2.5 | Upgrade to 1.3.5
S.o.S: Splunk on Splunk 2.3.0 | Upgrade to 3.1.0
From what I read, it was suggested that these 2 apps be upgraded together. So my questions are;
1. Does anyone know if the upgrade will address the "Error in 'rex' command." error?
2. Is there any risk to running the upgrade. (I really don't want to have any failure issues at this time of year.)
Thanks.