Upgrade the Splunk Add-on for Unix and Linux
If the Splunk Add-on for Unix and Linux was previously installed and configured, there are several prerequisite steps that must be completed before upgrading to version 6.0.0.
The Splunk Add-on for Unix and Linux 6.0.0 no longer defines
firedalerts indexes. You must make a local copy of
indexes.conf before performing the upgrade.
- If necessary, create the event indexes, see Create and edit event indexes.
- To index data in a specific index, edit
index = indexnamein the
If the Splunk Add-on for Unix and Linux is upgraded from version 5.2.4 to version 6.0.0 before making a local copy of
indexes.conf, the existing index configurations will not be available after the upgrade and the previously indexed data may be lost. If indexes are defined and not copied over, newly ingested data may be lost. If data is sent to an undefined index, data will be lost.
Default indexing location
The Splunk Add-on for Unix and Linux version 5.2.4 indexes data by default into an
os index, and version 6.0.0 uses the main index. If you want to index data with version 6.0.0 in the same index used by version 5.2.4, add
index = <os/firedalerts> to each input stanza in
- Locate each input stanza and add
index = <os/firedalerts>.
If this step is missed, the Splunk Add-on for Unix and Linux 6.0.0 will index data into the default index, typically main.
Monitoring bash history
The stanza name for monitoring bash histories has been renamed in the Splunk Add-on for Unix and Linux to improve performance. You must rename the existing
bash_history stanza name in
- Locate the stanza
- Change the stanza name to
If this step is missed, you will see both
[monitor:///home/*/.bash_history] in the add-on setup page.
The configuration status of the Splunk Add-on for Unix and Linux version 6.0.0 is set to
false by default and you will be asked to perform the setup after the upgrade is completed. Once the setup is saved, you will not be asked to perform the setup again.
If you do not want to reconfigure the add-on after the upgrade is completed, add
- Locate the
[install]stanza and add
Install the Splunk Add-on for Unix and Linux
Enable data and scripted inputs for the Splunk Add-on for Unix and Linux
This documentation applies to the following versions of Splunk® Add-on for Unix and Linux: 6.0.0