Splunk® Enterprise

Analytics Workspace

Splunk Enterprise version 8.1 will no longer be supported as of April 19, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.

Requirements for the Analytics Workspace

To use the Analytics Workspace, you must meet the following requirements.

Splunk role requirements

To configure the Analytics Workspace in Splunk Enterprise, you must be a member of the admin role. You can't change or edit the configuration of the Analytics Workspace in Splunk Cloud Platform.

Splunk capability requirements

To use some functionalities of the Analytics Workspace, you must have certain capabilities assigned at the user level.

Functionality Capability
Alerts schedule_search

See About configuring role-based user access in Securing Splunk Enterprise for information on Splunk roles and capabilities.

Splunk platform requirements

The Analytics Workspace runs on the following Splunk platforms:

  • Splunk Enterprise version 8.0.0 and later
  • Splunk Cloud Platform version 8.0.0 and later

For Splunk Enterprise system requirements, see System Requirements in the Splunk Enterprise Installation Manual.

Upgrading Splunk Enterprise

Analytics Workspace is installed by default in Splunk Enterprise version 8.0 and later. Prior to Splunk Enterprise 8.0, Metrics Workspace provided similar functionality to Analytics Workspace. In Splunk Enterprise 7.3, Metrics Workspace is installed by default, but in Splunk Enterprise 7.2 and earlier, Metrics Workspace is a standalone app.

If you used Metrics Workspace with Splunk Enterprise version 7.2 or earlier in a search head cluster environment, before you upgrade to Splunk Enterprise version 7.3 or later, remove the splunk_metrics_workspace app from the $SPLUNK_HOME/etc/shcluster/apps directory. Complete this step before running any configuration deployments.

Last modified on 21 July, 2021
About the Analytics Workspace   Open the Analytics Workspace

This documentation applies to the following versions of Splunk® Enterprise: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.3.0, 9.3.1, 9.3.2, 9.4.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters