Upgrade to version 2.1.0 of the Content Pack for Monitoring Splunk as a Service
Follow these steps only if you are upgrading the content pack from version 2.0.1 or earlier.
Review the following high-level upgrade steps before you begin:
- Remove the existing KPI Base Searches.
- Upgrade the Splunk App for Content Packs to v2.0.0.
- Upgrade the Content Pack for Monitoring Splunk as a Service.
Prerequisites
Create a full backup of your ITSI environment in case you need to revert the upgrade. For more information, see Create a Full Backup in the Administer Splunk IT Service Intelligence manual.
Step 1. Remove existing KPI Base Searches
- Open ITSI.
- Click Configuration > KPI Base Searches.
-
Locate each of the KPI Base Searches below so that you can delete them:
- SPLK-ES-Search_Head.Correlation_Searches
- SPLK-Search_Head.Base_Search.Scheduler
- Select Edit > Delete.
- Click Delete.
Step 2. Upgrade the Splunk App for Content Packs
- Verify which ITSI version is compatible with Splunk App for Content Packs in the Compatibility with ITSI and ITE Work table.
- Download Splunk App for Content Packs v2.0.0 from Splunkbase.
- Follow the Installation steps at Install the Splunk App for Content Packs to upgrade the Splunk App for Content Packs.
Step 3. Upgrade the Content Pack for Monitoring Splunk as a Service
Perform the steps in Install the content pack to re-install the content pack. Make sure to perform the steps below while in Step 5 of the Install the content pack from the Splunk App for Content Packs procedure.
- Select all the ITSI objects of the content pack Already Installed section in Choose which objects to install.
- Select the "Replace Existing" parameter in Choose a conflict resolution rule for the objects you install.