
Upgrade the Splunk Add-on for Cisco ISE
Upgrade from v4.1.0 to v4.2.0
Upgrade from Splunk Add-on for Cisco ISE v4.1.0 to v4.2.0 requires no additional steps to be performed.
Upgrade from v4.0.0 to v4.1.0
Upgrade from Splunk Add-on for Cisco ISE v4.0.0 to v4.1.0 requires no additional steps to be performed.
Upgrade an indexer cluster from Splunk Add-on for Cisco ISE version 3.0.0
- On the cluster master of your indexer cluster Splunk platform deployment, navigate to
$SPLUNK_HOME/etc/master-apps/Splunk_TA_cisco-ise/local/
. - Open
props.conf
and edit thecisco:ise
stanza to remove the following line:DATETIME_CONFIG = /etc/slave-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml
- Edit the
cisco:ise:syslog
stanza to remove the following line:DATETIME_CONFIG = /etc/slave-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml
- Save your changes.
- Push the configurations to your peer nodes.
PREVIOUS Configure Cisco ISE to send logs to Splunk Enterprise for the Splunk Add-on for Cisco ISE |
NEXT Configure data collection using Splunk Connect for Syslog |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!