Upgrade to Splunk App for VMware 3.4.7
Download the files from Splunkbase
- Download the Splunk App for VMware version 3.4.7 from Splunkbase to a location in your environment.
- Download the Splunk Add-on for for VMware version 3.4.7 from Splunkbase to a location in your environment.
- Download the Splunk OVA for VMware version 3.4.7 from Splunkbase to a location in your environment.
Upgrade the search head
Make sure '''splunk_vmware_admin''' role has '''admin_all_objects''' capability.
For search head cluster deployments
- Upgrade all the components on search head deployer. Components are located in etc/apps.
- Copy the local folder from etc/apps/Splunk_TA_vmware from Search head to etc/shcluster/apps/TA-VMW-FieldExtractions on deployer.
- Delete Splunk_TA_vmware from etc/shcluster/apps/ on your deployer.
- Delete savedsearches.conf and tsidx_retention.conf from
etc/shcluster/apps/SA-VMW-Performance/default/
on your deployer before applying the upgrade bundle. - Push app bundle from deployer. The deployer will restart all the search head cluster members after the upgrade is applied. If deployer does not restart the search head cluster members, perform a rolling restart.
For dedicated search head deployments
- Upgrade all the components on Search head. Components are located in etc/apps.
- Copy the local folder from Splunk_TA_vmware to TA-VMW-FieldExtractions from etc/apps on Search head.
- Delete Splunk_TA_vmware from etc/apps/.
- Delete savedsearches.conf and tsidx_retention.conf from etc/apps/SA-VMW-Performance/default/ on your Search head.
- Splunk restart on Search head.
Validate the Splunk App for VMware upgrade on your search head
Validate that you correctly upgraded the Splunk App for VMware to the latest version and that the app can collect data.
- Log in to the Splunk App for VMware on your search head.
- When the app displays the Splunk for VMware Setup page, select the Delete all deprecated Add-ons checkbox under Disable/delete old add-ons. The app removes all legacy add-ons from the installation. This removes saved searches of SA-VMW-Performance that are no longer in use.
- Save your configurations, and restart your Splunk platform deployment.
Manually remove legacy add-ons
If you launched Splunk App for VMware but did not check Delete all deprecated Add-ons on the setup page, you can manually remove the legacy add-ons from your installation.
- Stop the Splunk platform on your search head.
- Delete the
hydra_job.conf
file in the$SPLUNK_HOME/etc/apps/Splunk_TA_vmware/local
folder on the Splunk Search head. - Remove the
SA-VMW-Licensecheck
folder from the$SPLUNK_HOME/etc/apps
folder on your Splunk search head. Do this for each server upon which you installed the Splunk App for VMware. - The below table shows the specific legacy add-ons, located in the
$SPLUNK_HOME/etc/apps/Splunk_TA_vmware/local
folder of the Splunk App for VMware, to delete when upgrading: DA-VMW-HierarchyInventory
DA-VMW-LogEventTask
DA-VMW-Performance
SA-VMW-Licensecheck
- Restart your Splunk platform.
Upgrade the add-on on the scheduler, DCN, and indexer
Next, you must upgrade the add-on on the scheduler, DCN, and indexer. See Upgrade to Splunk Add-on for VMware 3.4.7.
Additional information
See "Platform and Hardware Requirements" in this manual for supported Splunk platform versions for this release. See "How to upgrade Splunk Enterprise" to upgrade to a new version of the Splunk platform.
For information on upgrading from tsidx namespaces to data model acceleration, see the "Upgrade from tsidx namespaces to data model acceleration" section of the troubleshooting section of this manual.
Troubleshoot Splunk App for VMware |
This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.4.7
Feedback submitted, thanks!