Install the Splunk Add-on for Amazon Kinesis Firehose on a distributed Splunk Enterprise deployment
Prerequisite
Select and prepare your distributed Splunk Enterprise deployment for the Splunk Add-on for Amazon Kinesis Firehose
Version 6.0.0 of the Splunk Add-on for AWS includes a merge of all the capabilities of the Splunk Add-on for Amazon Kinesis Firehose. Configure the Splunk Add-on for AWS to ingest across all AWS data sources for ingesting AWS data into Splunk.
If you use both the Splunk Add-on for Amazon Kinesis Firehose as well as the Splunk Add-on for AWS on the same Splunk instance, then you must uninstall the Splunk Add-on for Amazon Kinesis Firehose after upgrading the Splunk Add-on for AWS to version 6.0.0 or later in order to avoid any data duplication and discrepancy issues.
Data that you previously onboarded through the Splunk Add-on for Amazon Kinesis Firehose will still be searchable, and your existing searches will be compatible with version 6.0.0 of the Splunk Add-on for AWS.
If you are not currently using the Splunk Add-on for Amazon Kinesis Firehose, but plan to use it in the future, then the best practice is to download and configure version 6.0.0 or later of the Splunk Add-on for AWS, instead of the Splunk Add-on for Amazon Kinesis Firehose.
Steps
- Get the Splunk Add-on for Amazon Kinesis Firehose by downloading it from https://splunkbase.splunk.com/app/3719 or browsing to it using the app browser within Splunk Web.
- Install the add-on on all search heads where Amazon Kinesis Firehose knowledge management is required and on one or more indexers. See Install an add-on in a distributed Splunk Enterprise deployment in Splunk Add-Ons for detailed instructions describing how to install a Splunk add-on in a distributed deployment.
This documentation applies to the following versions of Splunk® Supported Add-ons: released, released
Feedback submitted, thanks!