Upgrade the Splunk Add-on for Microsoft Exchange
Step 1. Upgrade the Forwarders
Upgrade the forwarders with the deployment server
Prepare the new Add-ons
- Download the Splunk Add-on for Microsoft Exchange from Splunkbase.
- Extract the Splunk Add-on for Microsoft Exchange to the deployment apps directory %SPLUNK_HOME%\etc\deployment-apps on the deployment server.
- Within each Exchange Add-on directory in the deployment apps directory, create a
local
directory. For example, in %SPLUNK_HOME%\etc\deployment-apps\TA-Exchange-ClientAccess, create %SPLUNK_HOME%\etc\deployment-apps\TA-Exchange-ClientAccess\local. - For each Exchange add-on, copy the inputs.conf from the default directory of the add-on to the local directory you just created.
- For each Exchange add-on, use a text editor to edit the inputs.conf files in the local directory and enable stanzas for the version of Exchange server that you run.
- If you have made any customizations to the old set of Exchange add-ons, copy and paste those configurations from the local directory of those add-ons into the local directory of the new Exchange add-ons.
Create server classes, push the new add-ons, and delete old add-ons
- On the deployment server, create a server class for each of the new Exchange add-ons.
- Assign the add-ons to the appropriate server class. For example, the TA-Exchange-ClientAccess add-on should be assigned to the Exchange ClientAccess server class.
- Assign the Windows Server, Exchange Server, and Active Directory hosts in your Exchange deployment to the appropriate server classes, depending on the roles that they perform.
- Delete all of the old add-ons on the deployment server, for example, TA-DomainController-NT5, TA-Exchange-2013-Mailbox, and TA-Exchange-HubTransport).
- Use the deployment server to push the new add-ons to all of the hosts in the deployment.
- Restart the deployment server.
- Restart all forwarders.
Upgrade the forwarders without the deployment server
Perform these steps on all the Exchange servers:
- Download the Splunk Add-on for Microsoft Exchange from Splunkbase.
- Stop the Splunk forwarder.
- Extract the Splunk Add-on for Microsoft Exchange to the apps directory %SPLUNK_HOME%\etc\apps.
- Start the Splunk forwarder.
Step2. Upgrade the indexers (Only required if you are not using the latest version of the Splunk Add-on for Microsoft Exchange Indexes)
- Download the Splunk Add-on for Microsoft Exchange Indexes from Splunkbase and extract its components to the /apps folder for your deployment.
- For a non-indexer cluster deployment, extract to $SPLUNK_HOME/etc/apps.
- For the indexer-clustering deployments, extract to $SPLUNK_HOME/etc/master-apps.
- For indexer-clustering deployments, push the configuration bundle from the cluster master node.
- For non-clustered indexers, restart Splunk on each indexer.
- Disable maintenance mode on the cluster master node.
Release Notes for Splunk Add-ons for Microsoft Exchange | Overview of TA-Exchange-ClientAccess |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!