Migrate Splunk Stream in a Splunk Single Instance deployment
As of Verison 7.3, Splunk Stream is packaged as three components. After migration, managing and upgrading components will be easier and will work more readily with Splunk management tools for clustered environments.
Product name | Installation package name | Installed file name |
---|---|---|
Splunk App for Stream | splunk_app_stream
|
splunk_app_stream/
|
Splunk Add-on for Stream Forwarders | Splunk_TA_stream
|
Splunk_TA_stream/
|
Splunk Add-on for Stream Wire Data | Splunk_TA_stream_wire_data
|
Splunk_TA_stream_wire_data/
|
Independent Stream Forwarders are packaged as a binary file <streamfwd>
in the Splunk App for Stream package.
For more about Splunk Stream components, see Splunk Stream installation package overview in this manual.
Upgrade
To upgrade to Splunk Stream 7.3, you upgrade the Splunk App for Stream (splunk_app_stream
) and Splunk Add-on for Stream Forwarder (Splunk_TA_ stream
), and install the Splunk Add-on for Stream Wire Data (Splunk_TA_stream_wire_data
).
As a best practice, back up your existing configuration to a separate server or directory in case you need it later.
Upgrade the Splunk App for Stream and Splunk Add-on for Stream Wire Data
To download the files for this task:
- Download the Splunk Add-on for Stream Wire Data (
Splunk_TA_stream_wire_data
) at http://splunkbase.com/app/5234 - Download the Splunk App for Stream (
splunk_app_stream
) at http://splunkbase.splunk.com/app/1809
- If your are running Splunk Add-on for Stream Forwarders (
Splunk_TA_stream
) in data capture mode, disable it by setting the Splunk Add-on for Stream Forwarders todisabled = 1
in theSplunk_TA_stream
)app.conf
file. - (Optional) Back up your existing version of the Splunk Add-on for Stream Forwarders (
Splunk_TA_stream
) and the Splunk App for Stream (splunk_app_stream
) to a separate directory. - Install the Splunk Add-on for Stream Wire Data (
Splunk_TA_stream_wire_data
) on your Splunk Enterprise instance. - Use the backup you created in step two to move the following files to
Splunk_TA_stream_wire_data/local/
.distsearch.conf
tags.conf
props.conf
transforms.conf
eventtypes.conf
indexes.conf
(for indexer package only)
- (Optional) Once you have moved the files in step four to
Splunk_TA_stream_wire_data/local/
, delete them fromSplunk_TA_stream
. This keeps the installation clean and avoids potential conflicts with future release changes. - Upgrade the Splunk App for Stream (
splunk_app_stream
) on your Splunk Enterprise instance. Do not disable or delete Splunk App for Stream after installation, this file retains configurations for the forwarder installation. - Enable the Splunk Add-on for Stream Forwarders (
Splunk_TA_stream
) on your Splunk Enterprise instance by setting theapp.conf
file toenabled = 0
- Upgrade the Splunk Add-on for Stream Forwarders (
Splunk_TA_stream
) on your Splunk Enterprise instance. - Restart your Splunk Enterprise instance.
- Verify that all data flows as expected in your dashboards.
Upgrade the Splunk Add-on for Stream Forwarders
Download the Splunk Add-on for Stream Forwarders (Splunk_TA_stream
) at http://splunkbase.com/app/5238.
- Make a backup of your existing version of
Splunk_TA_stream
. - Extract the latest version of the Splunk Add-on for Stream Forwarders (
Splunk_TA_stream
) over your previous version. - (Optional) Remove all of the files listed in step four of "Upgrade Splunk App for Stream and Install Splunk Add-on for Stream Wire Data" in this topic.
- Restart your Splunk Enterprise instance.
On Windows systems, Splunk Stream only supports the Admin role.
Install Splunk Stream on a single instance deployment | Install the Splunk Add-on for Stream Forwarder |
This documentation applies to the following versions of Splunk Stream™: 8.0.1, 8.0.2, 8.1.0, 8.1.1, 8.1.3
Feedback submitted, thanks!