Enterprise Security post-installation and upgrades
Post-installation configuration and upgrade procedures for Enterprise Security.
After installing Enterprise Security, complete post-installation configuration steps and follow upgrade procedures for new ES versions.
Post-installation configuration
After installing ES, complete the following steps:
- Deploy add-ons to Splunk ES: You can install technology add-ons (TAs) that need to reside on indexers through the AppFramework. Install TAs that reside on forwarders manually or through third-party configuration management.
- Set up integration with Splunk Stream (optional).
- Configure and deploy indexes: Indexer clustering automatically pushes the indexes associated with the packaged DAs and SAs to indexers. This step is only necessary if you want to configure any custom index configuration. Additionally, any newly installed technology add-ons that are not included with the ES package might require index deployment.
- Configure users and roles as desired.
- Configure data models.
Upgrade steps
To upgrade ES, move the new ES package into the specified AppFramework bucket. This initiates a pod reset and begins the process of upgrading to the new version. In indexer clustering environments, also move the new Splunk_TA_ForIndexers app to the Cluster Manager AppFramework bucket that deploys apps to cluster members.
- The upgrade process preserves any knowledge objects that exist in app local directories.
- Check the ES upgrade notes for any version-specific changes.