Splunk® Content Packs for ITSI and IT Essentials Work

Splunk Content Packs for ITSI and IT Essentials Work

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Upgrade from a previous version of the Content Pack for Monitoring Citrix

If you have installed a previous version of the content pack, you can upgrade to the latest version.

The new version of the content pack contains some changes that can't be reversed after an upgrade. Some content pack functionality may not be available after upgrade. You won't receive notable events and episodes for your services and KPIs until the upgrade is complete.

Review and understand the upgrade steps before you begin:

  1. Make a note of which objects from the previous content pack version you have customized or enabled.
  2. Clone customized objects.
  3. Upgrade to the latest version of the content pack add-on from Splunkbase.
  4. Upgrade the content pack.
  5. Manually review and reapply prior modifications to the updated content pack objects.
  6. Manually reenable the appropriate content pack objects.

Prerequisites

Create a full backup of your ITSI environment in case you need to revert to the upgraded version later. For more information, see Create a full backup in the Administer Splunk IT Service Intelligence manual.

Step 1: Note all customized or enabled content pack objects

ITSI restores will overwrite and disable any objects from the restore file that also exists in your ITSI environment. Before you upgrade, you must identify all customized and enabled components. ITSI uses the name of the object to detect existing objects (for example, the name of the correlation search). Review the release notes for this content pack to see the ITSI objects included in the content pack, and identify objects you've enabled and modified. In the remaining upgrade steps, you will need to refer back to this list of objects for further action.

Step 2: (Optional) Clone customized objects from the original content pack

Cloning a customized object from the original content pack allows you to save the modified object under a new name, which ensures your changes aren't lost during upgrade. Keep the cloned objects disabled. Review the updated content pack objects with your customizations to determine the changes needed after the upgrade.

Step 3: Upgrade the content pack add-on

Upgrade the supporting add-on from Splunkbase to the latest version on your search head running ITSI. You don't need to restart Splunk software unless specifically indicated after the installation process.

Step 4: Upgrade the ITSI content pack

Follow the instructions in Step 2: Install the content pack.

Step 5: Add previous customizations to the upgraded content pack objects

You may need to add previous customizations to your ITSI objects after upgrading the content pack. Review any changes from the cloned objects as well as the release notes to add your customizations again, as necessary. After customizations are added to the latest version of the content pack objects, you can remove any objects that you cloned.

Step 6: Enable previously active content pack objects

After the upgrade, all previously enabled content pack objects are disabled, so you must enable the correct objects again to restore content pack functionality. Based on the content pack objects that were enabled before the upgrade, as well as any new functionality you want to begin using with the upgraded content pack version, evaluate and enable the appropriate objects.

Last modified on 27 October, 2021
PREVIOUS
Use the Content Pack for Monitoring Citrix
  NEXT
About the Content Pack for Monitoring Microsoft Windows

This documentation applies to the following versions of Splunk® Content Packs for ITSI and IT Essentials Work: current


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters