Splunk® Content Packs for ITSI and IT Essentials Work

Splunk Content Packs for ITSI and IT Essentials Work

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Upgrade to version 1.0.1 of the Content Pack for Third-party APM

If you have installed a previous version of the content pack, you can upgrade to the latest version.

Upgrading to the latest version of the content pack is a manual process that requires downtime for content pack functionality during the upgrade.

Review the high-level upgrade steps before you begin.

  1. Make a note of the objects from the previous content pack version you have customized or enabled.
  2. Clone customized objects.
  3. Upgrade to the latest version of Splunk App for Content Packs.
  4. Upgrade to the latest version of the Content Pack for Third-party APM.
  5. Manually review and reapply prior modifications to the updated content pack objects.
  6. Manually reenable the appropriate content pack objects.

Prerequisites

Create a full backup of your ITSI environment in case you need to revert the upgrade. For more information, see Create a Full Backup in the Administer Splunk IT Service Intelligence manual.

Step 1. (Optional) Note all customized or enabled content pack objects

Upgrading the content pack will both overwrite and disable any objects from the previous version of the content pack that exists in your ITSI environment. Before you upgrade, you have to identify all customized and enabled components. ITSI uses the name of the object to detect existing objects (for example, the name of the correlation search). Review the release notes for the content pack to see which ITSI objects are in the content pack, and identify any objects that you've enabled, as well as any objects that you've modified and customized. In the remaining upgrade steps, you will refer back to this list of objects for further action.

Step 2: (Optional) Clone customized objects from the original content pack

Cloning a customized object from the original content pack allows you to save the modified object under a new name, which ensures that your changes aren't lost after the upgrade. Keep the cloned objects disabled. They exist only to allow you to perform a manual review of the updated content pack objects with your customizations to determine what changes to incorporate after the upgrade.

Step 3: Upgrade the Splunk App for Content Packs

  1. Check which version of Splunk App for Content Packs is compatible with your ITSI version in the deployment requirements.
  2. Download the version 1.4.0 of the Splunk App for Content Packs from Splunkbase.
  3. Follow the installation steps to upgrade the Splunk App for Content Packs.
  4. Restart Splunk. See Restart Splunk Enterprise from Splunk Web in the Splunk Enterprise Admin manual for restart steps.

Step 4: Upgrade the Content Pack for Third-party APM

  1. The savedsearches.conf file from the previous version of the Content Pack for Third-party APM is redundant so remove savedsearches.conf file from $SPLUNK_HOME/etc/shcluster/apps/DA-ITSI-CP-thirdparty-apm/default/. If you have a single search head, then remove the savedsearches.conf file from $SPLUNK_HOME/etc/apps/DA-ITSI-CP-thirdparty-apm/default/ directory
  2. Follow these steps to replace the existing ITSI objects from the current version of the content pack with the new ITSI objects from the latest version of the content pack:
    1. From the ITSI main menu, click Configuration > Data Integrations.
    2. Click Add structure to your data.
    3. Select the 3rd Party APM content pack.
    4. Review what's included in the content pack and then click Proceed.
    5. Under Choose which objects to install select the following:
      1. Uncheck Service analyzers (1) from Net New (1). You will install the service analyzer later in the upgrade process.
      2. Select Add all 26 objects from Already Installed (26).
    6. Under Choose a conflict resolution rule for the objects you install, select Replace existing (existing conflicts are overwritten).
      Already Installed Objects.png
    7. Select Install selected.
  3. Install the service analyzer which is a new addition in this version of the content pack:
    1. From the ITSI main menu, click Configuration > Data Integrations.
    2. Click Add structure to your data.
    3. Select the 3rd Party APM content pack.
    4. Review what's included in the content pack and then click Proceed.
    5. Under Choose which objects to install, select Service Analyzer from Net New (1).
    6. Under Choose a conflict resolution rule for the objects you install, select Install as new (no content is overwritten).
      Net New Object.png
    7. Select Install selected.

Step 5: Reapply prior customizations to the upgraded content pack objects

Based on prior customizations to the content pack objects that you identified in step 1 of the upgrade process, you might need to reapply those customizations to the upgraded objects. Review modifications from the cloned objects, as well as the release notes to reapply customizations as necessary. When you are satisfied that prior customizations are appropriately integrated into the latest version of the content pack objects, you can remove any cloned objects.

Step 6: Enable previously active content pack objects

After the upgrade, all previously enabled content pack objects are disabled, so you have to enable the correct objects again to restore content pack functionality. Based on the content pack objects that were enabled before the upgrade, as well as any new functionality you want to begin using with the upgraded content pack version, evaluate and enable the appropriate objects.

Last modified on 29 October, 2021
PREVIOUS
Install and configure the Content Pack for Third-party APM
  NEXT
Use the Content Pack for Third-party APM

This documentation applies to the following versions of Splunk® Content Packs for ITSI and IT Essentials Work: current


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters