Splunk® Content Packs for ITSI and IT Essentials Work

Splunk Content Packs for ITSI and IT Essentials Work

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Migrate from the Splunk App for AWS to the Content Pack for Amazon Web Services Dashboards and Reports

The Content Pack for Amazon Web Services Dashboards and Reports replicates the dashboards and reports available in the Splunk App for AWS. Migrate from the legacy app to the content pack to take advantage of a consolidated experience within one app, either ITSI or IT Essentials Work. In addition, you can upgrade all content packs by upgrading the one app, the Splunk App for Content Packs.

On January 5, 2022, the Splunk App for AWS will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to the Content Pack for Amazon Web Services Dashboards and Reports.

If you are currently using the Splunk App for AWS, your deployment might look like the following image:

This image is a diagram of pre-migration deployment. A series of connected boxes represent the different parts of a deployment and include the Data Collection Node, Indexer, and Search Heads. Review the table that follows for more information.
Product Data collection node (forwarder) Indexer Search head
Splunk Add-on for AWS
Splunk App for AWS

You can review dashboards included with the Content Pack for Amazon Web Services Dashboards and Reports before you migrate. See, Dashboard reference for the Content Pack for Amazon Web Services Dashboards and Reports.

Migration options

You have two options for migrating to the Content Pack for Amazon Web Services Dashboards and Reports:

  1. One option is to disable the Splunk App for AWS to use the same environment. This is migration option is the fastest but, results in an interruption in user access to your AWS dashboards and reports.
  2. Your second option is to configure Content Pack for Amazon Web Services Dashboards and Reports in a new environment. Choose this option if you don't want to interrupt user access to your AWS dashboards and reports.

If you choose the option of using the same environment, you must disable the Splunk App for AWS before installing the Content Pack for Amazon Web Services Dashboards and Reports. Both the app and content pack use the same knowledge objects, with the same definitions, and cannot be on the same search head.

Disable the Splunk App for AWS to use the same environment

The first option for migrating from the Splunk App for AWS to the Content Pack for Amazon Web Services Dashboards and Reports is to disable the Splunk App for AWS to use the same environment. Failure to first disable the Splunk App for AWS can cause knowledge object conflicts.

Disable the legacy app and install the Splunk App for Content Packs

Follow these steps to use your existing Splunk App for AWS environment search heads to install the Content Pack for Amazon Web Services Dashboards and Reports:

  1. On all search heads where the Splunk App for AWS is located, go to Apps > Manage Apps.
  2. Locate the Splunk App for AWS and select Disable. After disabling the app, associated dashboards and knowledge objects won't be accessible, and the knowledge objects won't run or perform any action.
  3. Install IT Service Intelligence (ITSI) or IT Essentials Work on the same search head with AWS data according to your type of deployment. Refer to these topics in the Splunk IT Service Intelligence Install and Upgrade Manual:
    1. Install Splunk IT Service Intelligence on a single instance.
    2. Install Splunk IT Service intelligence in a distributed environment.
    3. Install IT Service Intelligence in a search head cluster environment.
    4. Install IT Essentials Work.
  4. Install the Splunk App for Content Packs on the search head. See, Install the Splunk App for Content Packs.
  5. Start the search head.
  6. Push the bundle.

After following the previous steps, the Splunk platform deployment looks like the following image:

This image is a diagram of post-migration deployment. A series of connected boxes represent the different parts of a deployment and include the Data Collection Node, Indexer, and Search Heads. Review the table that follows for more information.
Product Data collection node (forwarder) Indexer Search head
Splunk Add-on for AWS
Splunk App for AWS Disabled
ITSI or IT Essentials Work
Splunk App for Content Packs

Install and configure the content pack

You can now install the content pack and make configurations:

  1. Make sure that the AWS data collected using the Splunk Add-on for AWS is searchable from the search head where you installed the Splunk App for Content Packs.
  2. Install and configure the Content Pack for Amazon Web Services Dashboards and Reports.

Access the dashboards in the content pack

You can now access the dashboards from the content pack:

  1. Log into your Splunk platform instance and open ITSI or IT Essentials Work.
  2. Go to Dashboards on the main navigation bar and choose Dashboards from the drop-down menu.
  3. From the list of dashboards, those with the suffix - AWS are from the Content Pack for Amazon Web Services Dashboards and Reports. Select the dashboard title to open the dashboard.

Configure the Content Pack for Amazon Web Services Dashboards and Reports in a new environment

The second option for migrating from the Splunk App for AWS to the Content Pack for Amazon Web Services Dashboards and Reports is to configure the content pack in a new environment.

To configure the content pack in a new environment, create a test environment and perform these steps to set up the Content Pack for Amazon Web Services Dashboards and Reports:

  1. Install and configure the Content Pack for Amazon Web Services Dashboards and Reports.
  2. Migrate the content pack to your production environment.
Last modified on 21 October, 2021
PREVIOUS
Install and configure the Content Pack for Amazon Web Services Dashboards and Reports
  NEXT
Use the Content Pack for Amazon Web Services Dashboards and Reports

This documentation applies to the following versions of Splunk® Content Packs for ITSI and IT Essentials Work: current


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters