Upgrade to version 1.4.0
If you have installed a previous version of the content pack, you can upgrade to the latest version. Review the following high-level upgrade steps before you begin:
- Upgrade the Splunk App for Content Packs to v2.1.0.
- Delete the manually-created Entity Discovery Searches.
- Install Content Pack for Microsoft 365 v1.4.0.
- Clean up obsolete searches.
Prerequisites for upgrade
Create a full backup of your ITSI environment in case you need to revert the upgrade. For more information about creating a backup, see Create a Full Backup in the Administer Splunk IT Service Intelligence manual.
Step 1. Upgrade the Splunk App for Content Packs
- Check which ITSI version is compatible with Splunk App for Content Packs in the Compatibility with ITSI and ITE Work table.
- Download Splunk App for Content Packs v2.1.0 from Splunkbase.
- Follow the installation steps to upgrade the Splunk App for Content Packs.
Step 2. Delete the manually-created Entity Discovery Searches
- Click on Settings > Searches, reports, and alerts.
- Search your manual Entity Discovery Search for the Microsoft 365 Content Pack.
- Click Edit > Delete.
- Click Delete.
Step 3. Install v1.4.0 of the content pack and enable discovery search
Follow these steps to re-install the content pack and enable the discovery searches. Make sure to perform the following steps while in Step 5 of Install the content pack from the Splunk App for Content Packs.
- Select all the ITSI objects of the content pack Already Installed section in Choose which objects to install.
- Select Replace Existing parameter in Choose a conflict resolution rule for the objects you install.
Step 4. Clean up obsolete searches
To clean obsolete searches, refer to Run a search command to clean up obsolete searches. This is required to ensure that the deleted entity discovery search does not contribute to the Entity Status calculation.