Splunk® Content Packs for ITSI and IT Essentials Work

Splunk Content Packs for ITSI and IT Essentials Work

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Migrate from the Splunk App for Windows Infrastructure to the Content Pack for Windows Dashboards and Reports

The Content Pack for Windows Dashboards and Reports replicates the dashboards and reports available in the Splunk App for Windows Infrastructure. Migrate from the legacy app to the content pack to take advantage of a consolidated experience within one app, either ITSI or IT Essentials Work. In addition, you can upgrade all content packs by upgrading the one app, the Splunk App for Content Packs.

Before you migrate

Before you migrate to the Content Pack for Windows Dashboards and Reports, review the dashboards included with the content pack in the Dashboard reference for the Content Pack for Windows Dashboards and Reports.

If you are currently using the Splunk App for Windows Infrastructure, your deployment might look like this:

Data collection node (forwarder) Indexer Search head
Splunk Add-on for Windows
Splunk App for Windows Infrastructure
Splunk Supporting Add on For Active Directory


You have two options for migrating to the Content Pack for Amazon Web Services Dashboards and Reports.

  1. One option is to disable the Splunk App for Windows Infrastructure to use the same environment.
  2. Your second option is to configure the Content Pack for Windows Dashboards and Reports in a new environment.

Disable the Splunk App for Windows Infrastructure to use the same environment

The first option for migrating from the Splunk App for Windows Infrastructure to the Content Pack for Windows Dashboards and Reports is to disable the Splunk App for Windows Infrastructure to use the same environment.

You can't enable the Splunk App for Windows Infrastructure and the Content Pack for Windows Dashboards and Reports on the same search head. Both the app and the content pack use the same knowledge objects with the same definitions. If you enable both the app and the content pack on the same search head and perform different configurations, knowledge objects might conflict when storing or retrieving configurations. After disabling the Splunk App for Windows Infrastructure, the associated dashboards and knowledge objects won't be accessible and the knowledge objects won't run or perform any action.

Disable the legacy app and install the Splunk App for Content Packs

Follow these steps to use your existing Splunk App for Windows Infrastructure environment search heads to install the Content Pack for Windows Dashboards and Reports:

  1. Disable Splunk App for Windows Infrastructure on the search head.
  2. Install ITSI or IT Essentials Work on the same search head with Windows data according to your type of deployment. Refer to these topics in the Splunk IT Service Intelligence Install and Upgrade manual:
    1. Install Splunk IT Service Intelligence on a single instance.
    2. Install Splunk IT Service intelligence in a distributed environment.
    3. Install IT Service Intelligence in a search head cluster environment.
    4. Install IT Essentials Work.
  3. Install the Splunk App for Content Packs on the search head.
  4. Start the search head.
  5. Push the bundle.

After following these steps, the Splunk deployment looks like this:

Data collection node (forwarder) Indexer Search head
Splunk Add-on for Windows
ITSI or IT Essentials Work
Splunk App for Windows Infrastructure Disabled
Splunk App for Content Packs
Splunk Supporting Add on For Active Directory

Install and configure the content pack

  1. Ensure the Windows data collected using Splunk Add-on for Windows is searchable from the search head where you installed the Splunk App for Content Packs.
  2. Follow the steps in the Install and configure the Content Pack for Windows Dashboards and Reports topic.

Access the dashboards in the content pack

You can now access the dashboards from the content pack:

  1. Log in to Splunk Web and open ITSI or IT Essentials Work.
  2. Go to Dashboards > Dashboards.
  3. From the list of dashboards, those with the App name DA-ITSI-CP-windows-dashboards are from the Content Pack for Windows Dashboards and Reports. Select the dashboard name to open the dashboard.

Configure the Content Pack for Windows Dashboards and Reports in a new environment

The second option for migrating from the Splunk App for Windows Infrastructure to the Content Pack for Windows Dashboards and Reports is to configure the content pack in a new environment.

To configure the content pack in a new environment, create a test environment and perform these steps to set up the Content Pack for Windows Dashboards and Reports:

  1. Follow the steps in the Install and configure the Content Pack for Windows Dashboards and Reports topic.
  2. Migrate the content pack to your production environment.
Last modified on 25 August, 2021
PREVIOUS
Install and Configure the Content Pack for Windows Dashboards and Reports
  NEXT
Get Windows Data

This documentation applies to the following versions of Splunk® Content Packs for ITSI and IT Essentials Work: current


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters