Splunk® Supported Add-ons

Splunk Add-on for Box

Upgrade the Splunk Add-on for Box

Upgrade to the latest version of the Splunk Add-on for Box.

Upgrade from version 3.4.1 or above to version 3.5.0 or above of the Splunk Add-on for Box

There are no additional steps required for this version upgrade. See the Install the Splunk Add-on for Box topic in this manual.

Upgrade from version 3.1.0 to version 3.2.0 or later of the Splunk Add-on for Box

To upgrade from version 3.1.0 to version 3.2.0 or later, perform the following steps:

If you are upgrading from version 3.0.1 or below to version 3.2.0 or later, perform the steps for upgrading from version 3.0.1 or earlier to version 3.1.0 in addition to these steps.

  1. Disable all inputs that you have currently configured in your version of the Splunk Add-on for Box.
  2. Upgrade the add-on using one of the following methods:
    • Download the add-on from Splunkbase, and follow the steps in the Install the Splunk Add-on for Box topic in this manual.
    • In Splunk Web, navigate to the Apps bar, and click Upgrade.
  3. Refresh your browser cache.
  4. In each input for the events Endpoint, edit the input and enter the Delay (seconds) parameter.
    • (Optional) Set the Delay to non-zero if events from your Box deployment are missing in your Splunk platform deployment.

    The value of the Delay parameter should be strictly less than value Interval parameter.

  5. Save your changes.
  6. Enable all the inputs.

Upgrade from version 3.0.1 or earlier to version 3.1.0 of the Splunk Add-on for Box

To upgrade from version 3.0.1 or earlier to version 3.1.0, perform the following steps:

  1. Disable all inputs that you have currently configured in your version of the Splunk Add-on for Box.
  2. Upgrade the add-on using one of the following methods:
    • Download the add-on from Splunkbase, and follow the steps in the 'Install topic in this manual.
    • In Splunk Web, navigate to the Apps bar, and click Upgrade.
  3. Stop the Splunk platform instance.
  4. on HWF, Navigate to $SPLUNK_HOME/etc/apps/Splunk_TA_box/local/, and open your inputs.conf file in a text editor.
  5. In each input, find every instance of a interval parameter, and replace with a duration parameter.
  6. Save your changes.
  7. On HWF, Navigate to $SPLUNK_HOME/etc/apps/Splunk_TA_box/bin/ and remove the below folders and files:
    • sockshandler.py
    • socks.py
    • six.py
    • urllib3
    • requests_toolbelt
    • idna
    • enum
    • chardet
    • certifi
    • boxsdk
    • bin
    • requests
    • Splunk_TA_box
  8. Start the Splunk platform instance.
  9. Refresh your browser cache.
  10. Enable your inputs

Upgrade from versions earlier than 2.0.0

The Splunk Add-on for Box version 2.0.0 introduced breaking changes. If you are upgrading from version 1.2.0 or earlier to version 2.0.0 or above of the Splunk Add-on for Box, you must follow these instructions to prevent data loss.

To upgrade from version 1.2.0 or earlier to version 2.0.0 or above, follow these steps:

  1. Before upgrading, disable the inputs configured in Box version 1.2.0 or earlier.
  2. Upgrade the add-on.
  3. Go to the Box > Configuration > Box Account page and configure your previously configured Box account.
  4. Go to the Box > Input page. There are a list of inputs that had been configured before the upgrade. The Name field contains the values for the endpoint, including events, folders, users, and groups.
    1. At first, all configured inputs have a warning symbol next to the Name field.
    2. At first, the Account Name field shows Missing Box Account configuration, and the Endpoint field shows Missing Endpoint configuration.
  5. Reconfigure each input:
    1. Select the correct Box account.
    2. Select the Endpoint value corresponding to the Input Name to resume data collection.
    3. (Optional) Edit the Interval field if required. In previous versions of the Splunk Add-on for Box, the default interval was 120 seconds for events and 64,800 seconds for folders, users, and groups. After upgrading, the interval for configured data inputs is 30 seconds. You might need to edit this default interval after upgrading to version 2.0.0.
    4. Click Save.
  6. Enable the reconfigured inputs.
Last modified on 22 July, 2024
Install the Splunk Add-on for Box   Configure credentials on Box for the Splunk Add-on for Box

This documentation applies to the following versions of Splunk® Supported Add-ons: released, released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters