<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to upgrade add-ons on Indexers and Forwarders after Splunk ES upgrade ? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489157#M8194</link>
    <description>&lt;P&gt;Splunk_TA_ForIndexers contains indexes.conf as well, if you do not want to use Splunk_TA_ForIndexers on Indexers then you need to maintain all ES indexes in your dedicated app on Indexers &amp;amp; maintain/upgrade rest of the Add-on based on your requirement on Indexers. &lt;/P&gt;

&lt;P&gt;My preference is if you are installing Add-on separately on Indexers and you do not want to upgrade add-on on indexers then do not upgrade same add-on on ES SH. Also my advice is do not install add-on separately on Indexers and use Splunk_TA_ForIndexers on Indexers (Only install Add-on on Indexer which are not installed on ES SH).&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 03:41:58 GMT</pubDate>
    <dc:creator>harsmarvania57</dc:creator>
    <dc:date>2020-09-30T03:41:58Z</dc:date>
    <item>
      <title>How to upgrade add-ons on Indexers and Forwarders after Splunk ES upgrade ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489154#M8191</link>
      <description>&lt;P&gt;After upgrading ES search head, what is the recommended way to upgrade add-ons on Indexers and forwarders ?&lt;/P&gt;

&lt;P&gt;Based on the docs and current Splunk environment, it seems the ideal option is to use  &lt;CODE&gt;Create and set up automatic deployment of the Splunk_TA_ForIndexers&lt;/CODE&gt; method, however the doc says, &lt;CODE&gt;Before you deploy Splunk_TA_ForIndexers, make sure that existing add-ons installed on indexers are not included in the Splunk_TA_ForIndexers package. Deploying the same add-on twice might lead to configuration conflicts, especially if the add-ons are different versions.&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I dont get this part. If I am using the Splunk_TA_ForIndexers to upgrade addons on Indexers, obviously the add-ons are going to be different versions.&lt;/P&gt;

&lt;P&gt;Can someone please advise what I am missing here ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:45:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489154#M8191</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2020-09-30T03:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to upgrade add-ons on Indexers and Forwarders after Splunk ES upgrade ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489155#M8192</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Splunk_TA_ForIndexers&lt;/CODE&gt; contains Indexer related props.conf and transforms.conf settings from installed Apps/Add-ons on ES search head. &lt;/P&gt;

&lt;P&gt;For example: If you are running Splunk_TA_windows version 5 on Indexer and ES Search head running Splunk_TA_windows version 6 then &lt;CODE&gt;Splunk_TA_ForIndexers&lt;/CODE&gt; contain indexer related settings in props.conf and transforms.conf for Windows add-on version 6 &amp;amp; when you'll install &lt;CODE&gt;Splunk_TA_ForIndexers&lt;/CODE&gt; on Indexer it has conflict of same configuration and config which will take effect that is depend on precedence order so your data may not parse properly on Indexers.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:41:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489155#M8192</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-09-30T03:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to upgrade add-ons on Indexers and Forwarders after Splunk ES upgrade ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489156#M8193</link>
      <description>&lt;P&gt;so clearly it seems Splunk_TA_ForIndexers add-on should not be used for upgrading add-ons on Indexers and Forwarders.&lt;/P&gt;

&lt;P&gt;Should Splunk_TA_ForIndexers only be used for fresh installation on Indexers and NOT for upgrades?&lt;/P&gt;

&lt;P&gt;The only and best way is to manually download corresponding versions of addons from Splunkbase and install it on Indexers and Forwarders  ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489156#M8193</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2020-09-30T03:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to upgrade add-ons on Indexers and Forwarders after Splunk ES upgrade ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489157#M8194</link>
      <description>&lt;P&gt;Splunk_TA_ForIndexers contains indexes.conf as well, if you do not want to use Splunk_TA_ForIndexers on Indexers then you need to maintain all ES indexes in your dedicated app on Indexers &amp;amp; maintain/upgrade rest of the Add-on based on your requirement on Indexers. &lt;/P&gt;

&lt;P&gt;My preference is if you are installing Add-on separately on Indexers and you do not want to upgrade add-on on indexers then do not upgrade same add-on on ES SH. Also my advice is do not install add-on separately on Indexers and use Splunk_TA_ForIndexers on Indexers (Only install Add-on on Indexer which are not installed on ES SH).&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489157#M8194</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-09-30T03:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to upgrade add-ons on Indexers and Forwarders after Splunk ES upgrade ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489158#M8195</link>
      <description>&lt;P&gt;Sorry,  but I dont think you have read my question clearly.&lt;/P&gt;

&lt;P&gt;I want to use Splunk_TA_ForIndexers  to upgrade add-ons on indexers, however the doc says, Before you deploy Splunk_TA_ForIndexers, make sure that existing add-ons installed on indexers are not included in the Splunk_TA_ForIndexers package. Deploying the same add-on twice might lead to configuration conflicts, especially if the add-ons are different versions.&lt;/P&gt;

&lt;P&gt;I dont get this part. If I am using the Splunk_TA_ForIndexers to upgrade addons on Indexers, obviously the add-ons are going to be different versions.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:46:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489158#M8195</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2020-09-30T03:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to upgrade add-ons on Indexers and Forwarders after Splunk ES upgrade ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489159#M8196</link>
      <description>&lt;P&gt;I understood your question correctly, can you please let us know why different version of add-on will be there on Indexers ? If you are using Splunk_TA_ForIndexers then you do not need to install add-on (which are included Splunk_TA_ForIndexers) separately on Indexers. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:53:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-upgrade-add-ons-on-Indexers-and-Forwarders-after-Splunk/m-p/489159#M8196</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-09-30T03:53:34Z</dc:date>
    </item>
  </channel>
</rss>

