Splunk® Data Stream Processor

Install and administer the Data Stream Processor

Download manual as PDF

This documentation does not apply to the most recent version of DSP. Click here for the latest version.
Download topic as PDF

Upgrade the Data Stream Processor

If the Splunk Data Stream Processor was previously installed and configured, do the following to upgrade your software.


  1. Download the new Data Stream Processor tarball on the master node of your cluster.
  2. Extract the tarball.
    tar xf <dsp-version>.tar
  3. Navigate to the extracted file.
    cd <dsp-version>
  4. (Optional) If your environment has a small root volume (6GB or less of free space) in /tmp, your upgrade may fail when you run out of space. Choose a different directory to write temporary files to during the upgrade process.
    export TMPDIR=/<directory-on-larger-volume>
  5. From the extracted file directory, run the upgrade script.
  6. Upgrading can take a while. Upon completion, the following message is shown.
    Waiting for DSP to startup
    DSP startup completed
  7. (Optional) While waiting for the upgrade to complete, you can use the following command to monitor the progress of your upgrade. Run this command after you see the Waiting for DSP to startup message.
    kubectl get pods -n dsp
    When the following services have status RUNNING, then the upgrade is complete: dsp, ingest-hec, ingest-s2s, splunk-streaming-rest, usr-mgmt-svc.
Last modified on 11 February, 2020
Configure connections to external services
About the DSP Dashboards

This documentation applies to the following versions of Splunk® Data Stream Processor: 1.0.1

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters