Splunk® IT Essentials Work

Install Splunk IT Essentials Work

Acrobat logo Download manual as PDF

This documentation does not apply to the most recent version of Splunk® IT Essentials Work. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Upgrade Splunk IT Essentials Work on a single instance

Follow these steps to upgrade Splunk IT Essentials Work (ITE Work) on an on-premises search head. ITE Work supports upgrades from up to three minor versions prior to the version you're upgrading to. If you are upgrading from a version lower than 3 minor versions from the version you want to upgrade to, you have perform step upgrades. Splunk Cloud Platform customers have to work with Splunk Support to coordinate upgrades to ITE Work.

Before upgrading

Install the latest version of IT Essentials Work

On a single-instance deployment, a single Splunk Enterprise instance serves as both the search head and indexer.

You have to upgrade ITE work by extracting the ITE Work installation package. ITE Work doesn't support installation using the app manager in Splunk Web or the splunk install app command in the command line.

  1. Log in to splunk.com with your Splunk.com ID.
  2. Download the latest Splunk IT Essentials Work product.
  3. Stop your Splunk platform instance:
    cd $SPLUNK_HOME/bin
    ./splunk stop
  4. Extract the ITSI installation package into $SPLUNK_HOME/etc/apps. For example:
    tar -xvf splunk-it-service-intelligence_<latest_version>.spl -C $SPLUNK_HOME/etc/apps

    On Windows, rename the file extension from .spl to .tgz first and use a third-party utility like 7-Zip to perform the extraction.

  5. Start your Splunk software.
    cd $SPLUNK_HOME/bin
    ./splunk start
  6. The first time you go to ITE Work after installing the new files, a migration screen steps you through the upgrade process. For Skip over localized failures, choose whether to skip over the following types of failures:
    • Missing dependencies in service KPIs, such as a missing macro
    • Multiple entity split or filter fields in KPI base searches
    • Missing dependencies in KPI base searches
    • Missing dependencies in correlation searches
    • Duplicate services

    Skipping over these failures means the problematic objects aren't migrated. You'll receive a list of skipped objects when the upgrade completes.

  7. Click Start Upgrade. The migration script runs to migrate existing ITE Work knowledge objects to the new version.
  8. When the upgrade completes, open the ITSI homepage.

To check migration related logs, run the following Splunk search:

index=_internal "[itsi.migration]"

Upgrade indexers

You have place the SA-IndexCreation add-on on all indexers. For non-clustered distributed environments, copy SA-IndexCreation to $SPLUNK_HOME/etc/apps/ on individual indexers. Indexers have to be running a compatible version of Splunk Enterprise. If you upgrade your indexers, verify whether you have to also upgrade your search heads. For information, see Splunk Enterprise version compatibility in the Splunk Enterprise Managing Indexers and Clusters of Indexers manual.

If you have an indexer cluster, use the configuration bundle method to replicate SA-IndexCreation across all peer nodes. On the master node, place a copy of SA-IndexCreation in $SPLUNK_HOME/etc/master-apps/. For information about updating peers in an indexer cluster, see Manage app deployment across all peers in the Splunk Enterprise Managing Indexers and Clusters of Indexers manual.

Validate the upgrade

The ITE Work upgrade process is now complete. Objects disabled during the upgrade process are automatically reenabled. ITE Work shows the following message: IT Service Intelligence upgrade has completed successfully.

  1. In Splunk Web, select Help > About to verify that the upgrade was successful.
  2. Clear the browser cache of the browser you use to access Splunk Web. If you don't clear the browser cache, some pages might fail to load.

You can also check the installed version, latest version, and previous version by running the following search:

| rest splunk_server=local /services/apps/local/itsi | stats values(version) as itsi_installed_version | join [|inputlookup itsi_migration_check]

After upgrading

If the upgrade fails, see Roll back an upgrade of Splunk IT Essentials Work.

Last modified on 08 December, 2021
Before you upgrade Splunk IT Essentials Work
Upgrade Splunk IT Essentials Work on a search-head cluster

This documentation applies to the following versions of Splunk® IT Essentials Work: 4.12.0 Cloud only

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters