Upgrade Splunk Asset and Risk Intelligence
Upgrade the Splunk Asset and Risk Intelligence app by completing these high-level steps:
Prerequisites
Before you can start an upgrade, you must deactivate the processing searches. To deactivate the processing searches, complete the following steps:
- In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
- Select Turn all off for Process searches.
Download and upgrade the app
You can upgrade Splunk Asset and Risk Intelligence on either a Splunk Enterprise or Splunk Cloud Platform deployment. Complete the following steps based on your deployment type:
Splunk Cloud Platform
- From the Splunk Web menu, select Apps and then Manage apps.
- Locate Splunk Asset and Risk Intelligence from the list of apps.
- Select View details on Splunkbase and then upgrade the app through Splunkbase.
- Restart the search head.
Splunk Enterprise
- Upgrade the app using one of the following methods:
- Upload the new app version directly on the search head from the Splunk Enterprise home page and then overwrite the existing installation.
- Use Splunkbase to upgrade the app.
- Restart the search head.
Reconfigure app settings
After you upgrade the app, you must complete a few steps in Splunk Asset and Risk Intelligence to restore the appropriate functionality:
- Run upgrade checks.
- In Splunk Asset and Risk Intelligence, select Admin, then select Post-install configuration.
- Select Start configuration process. This process verifies and populates all the internal lookups and enrichment rules for Splunk Asset and Risk Intelligence.
- (Optional) Select the Show actions log check box to see which actions take place during the configuration process. You can also opt to Show skipped actions by selecting the check box.
- Reactivate the Splunk Asset and Risk Intelligence processing searches.
- Select Admin and then Configuration settings.
- Select Turn all on for Process searches.