Splunk® App for Content Packs

Overview of the Splunk App for Content Packs

Migrate from legacy apps to content packs

Several Splunk Content Packs for ITSI and IT Essentials Work replicate the dashboards and reports available in vendor-specific apps which are all scheduled for end of life. When you migrate from these legacy apps to content packs, you'll have a consolidated experience within one app, either ITSI or IT Essentials Work. In addition, as content packs are updated, you can upgrade all content packs by upgrading the one app, the Splunk App for Content Packs.

The content from these legacy apps has been migrated to content packs. This topic covers the generic steps to migrate from a legacy app to a content pack. Go to the app-specific migration topic for more specific migration steps.

Legacy app (End-of-life date) Content pack App-specific migration topic
Splunk App for AWS
(July 15, 2022)
Content Pack for Amazon Web Services Dashboards and Reports Migrate from the Splunk App for AWS to Content Pack for Amazon Web Services Dashboards and Reports
Splunk App for Microsoft Exchange
(October 22, 2021)
Content Pack for Microsoft Exchange Migrate from the Splunk App for Microsoft Exchange to the Content Pack for Microsoft Exchange
Splunk App for NetApp Data ONTAP
(June 10, 2021)

OR
Splunk Supporting Add-on for NetApp
(January 20, 2023)

Content Pack for NetApp Data ONTAP Dashboards and Reports Migrate from the Splunk App for NetApp Data ONTAP or the Splunk Supporting Add-on for NetApp to the Content Pack for NetApp Data ONTAP Dashboards and Reports
Splunk App for Unix and Linux
(March 13, 2022)
Content Pack for Unix Dashboards and Reports Migrate from the Splunk App for Unix and Linux to the Content Pack for Unix Dashboards and Reports
Splunk App for VMware

(August 31, 2022)
OR
Splunk Supporting Add-on for VMware
(January 11, 2023)

Content Pack for VMware Dashboards and Reports Migrate from the Splunk Supporting Add-on for VMware or the Splunk App for VMware to the Content Pack for VMware Dashboards and Reports
Splunk App for Windows Infrastructure
(October 20, 2021)
About the Content Pack for Windows Dashboards and Reports Migrate from the Splunk App for Windows Infrastructure to the Content Pack for Windows Dashboards and Reports

Before you migrate

Before you migrate to a content pack, review the dashboards packaged in the content pack in the dashboard reference for the content pack.

If you are currently using a legacy app, your deployment might look like this:

"Diagram of pre-migration deployment. Review the table that follows for more info."
Data collection node (forwarder) Indexer Search head
Splunk Add-on
Splunk App

You have two options for migrating from a legacy app to its corresponding content pack.

  • Disable the legacy app to use the same environment.
  • Configure the content pack in a new environment.

Disable the legacy app to use the same environment

The first option for migrating from a legacy app to a content pack is to disable the legacy app to use the same environment.

You can't install the legacy app and the content pack on the same search head. Both the apps and the content packs use the same knowledge objects with the same definitions. If you install both the app and the content pack on the same search head and perform different configurations, knowledge objects might conflict when storing or retrieving configurations. After disabling the legacy app, the associated dashboards and knowledge objects won't run or perform any action.

Disable the legacy app and install the Splunk App for Content Packs

Follow these steps to use your existing legacy app environment to install the content pack:

  1. Disable the legacy app on the search head.
  2. Install ITSI or IT Essentials Work on the same search head with legacy app data according to your deployment type. Refer to these topics in the Splunk IT Service Intelligence Install and Upgrade manual:
    1. Install Splunk IT Service Intelligence on a single instance.
    2. Install Splunk IT Service intelligence in a distributed environment.
    3. Install IT Service Intelligence in a search head cluster environment.
    4. Install IT Essentials Work.
  3. Install the Splunk App for Content Packs on the search head.
  4. Start the search head.
  5. Push the bundle.

After following these steps, the Splunk deployment looks like this:

"Diagram of post-migration deployment. Review the table that follows for more info."
Data collection node (forwarder) Indexer Search head
Splunk Add-on
Splunk App Disabled
ITSI or IT Essentials Work
Splunk App for Content Packs

Install and configure the content pack

  1. Ensure the data collected with the corresponding add-on is searchable from the search head where you installed the Splunk App for Content Packs.
  2. Follow the steps in the install and configure topics for the content pack.

Access the dashboards in the content pack

You can now access the dashboards from the content pack:

  1. Log in to Splunk and open ITSI or IT Essentials Work.
  2. Go to Dashboards > Dashboards.
  3. From the list of dashboards, select the dashboard name to open the dashboard.

Configure the content pack in a new environment

The second option for migrating from the legacy app to a content pack is to configure the content pack in a new environment.

To configure the content pack in a new environment, create a test environment and perform these steps to set up the content pack:

  1. Follow the steps in the install and configure topics for the content pack.
  2. Migrate the content pack to your production environment.
Last modified on 22 May, 2024
Install the Splunk App for Content Packs   Working with synthetic data

This documentation applies to the following versions of Splunk® App for Content Packs: 2.2.0, 2.2.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters