How to upgrade the Splunk App for Windows Infrastructure
The commands shown in this topic are PowerShell. If you use *nix, substitute the PowerShell directives with their *nix counterparts. If you use different directories for Splunk Enterprise and deployment server, substitute the directories shown with your specific directories.
The search head is the Splunk Enterprise instance that runs the Splunk App for Windows Infrastructure and shows all of the app data. These upgrade instructions should be performed on any host that has been designated as a search head in your deployment.
- In case of standalone search head, remove the existing default.xml file from the local folder
etc/apps/splunk_app_windows_infrastructure/local/data/ui/navon the search head.
- (Optional) Backup local changes (local folder) created on the search head and search head deployer.
- Put the new Splunk App for Windows Infrastructure in the
etc/shcluster/apps/directory on your search head deployer. If you have a single search head, put the new Splunk App for Windows Infrastructure in
windows_apps.csvfrom the app:
windows_apps.csvlookup if available from
etc/shcluster/apps/splunk_app_windows_infrastructure/lookupson the search head deployer. In case of standalone search head, remove it from
- Remove following
windows_appslookup definition from
etc/shcluster/apps/splunk_app_windows_infrastructure/local/transforms.confif available on the search head deployer. In case of standalone searchhead, remove it from
etc/apps/splunk_app_windows_infrastructure/local/transforms.confif available on SH.
[windows_app_lookup] filename = windows_apps.csv [windows_apps] filename=windows_apps.csv max_matches=1
Troubleshoot permissions issues after an upgrade
The Splunk App for Windows Infrastructure installs a new user role,
winfra-admin. The Splunk user that uses the Splunk App for Windows Infrastructure must have this role, otherwise the app will not function correctly.
If, during the first time process, you see that the app does not find any data and you know that the data exists (such as in the case of an upgrade), be sure to add the
winfra-admin role to the user that uses the app, as described in the troubleshooting page.
Install the Splunk App for Windows Infrastructure using self service installation on Splunk Cloud
Upgrade from version 1.0.x
This documentation applies to the following versions of Splunk® App for Windows Infrastructure (Legacy): 1.5.1, 1.5.2, 2.0.0, 2.0.1, 2.0.2
Feedback submitted, thanks!