How to upgrade the Splunk App for Windows Infrastructure
The commands shown in this topic are PowerShell. If you use *nix, substitute the PowerShell directives with their *nix counterparts. If you use different directories for Splunk Enterprise and deployment server, substitute the directories shown with your specific directories.
Upgrade overview
There is one supported upgrade scenario available for the Splunk App for Windows Infrastructure:
- From version 1.0.x to this version.
- From version 1.1.x to this version.
- From version 1.2.x to this version.
If you run a previous version of the Splunk App for Windows, follow the setup instructions as a new install. You will be given the opportunity to resolve any data location issues as part of the guided setup procedure.
Upgrade tips
From version 1.0.x to this version
When you upgrade the app from version 1.0.x to this version, note the following:
- The app user experience is much different than it is in version 1.0.x.
- Disk space and memory requirements on dedicated search heads increase significantly because of app key value store, and increased lookup sizes. These requirements increase based on the number of hosts in your deployment. You might need to add more storage or replace search heads with hosts that have more memory and CPU cores available. See "Size and scale a Splunk App for Windows Infrastructure deployment."
From version 1.1.x to this version
When you upgrade the app from version 1.1.1 to this version, note that the upgrade process deletes the local settings in the app key value store. Once you complete the upgrade, you must:
- Rebuild all lookups for the app. See "Configure the Splunk App for Windows Infrastructure".
Troubleshoot permissions issues after an upgrade
When you upgrade the Splunk App for Windows Infrastructure to version 1.1, the app installs a new user role, winfra-admin
. The Splunk user that uses the Splunk App for Windows Infrastructure must have this role, otherwise the app will not function correctly.
If, during the first time process, you see that the app does not find any data and you know that the data exists (such as in the case of an upgrade), be sure to add the winfra-admin
role to the user that uses the app, as described in the troubleshooting page.
Install the Splunk App for Windows Infrastructure on a search head cluster | Upgrade from version 1.0.x |
This documentation applies to the following versions of Splunk® App for Windows Infrastructure (Legacy): 1.3.0
Feedback submitted, thanks!