All Apps and Add-ons

Upgrade DCN

simontam
Explorer

Is there any way to upgrade the data collection node? I am going to upgrade the Splunk app for VMware but cannot find any information about upgrading the dcn.

Should I just deploy a new one? But I am not sure what configuration has been done on it.

0 Karma

Masa
Splunk Employee
Splunk Employee

A good question! We used to have it in old versions.

Prerequisite
Find splunk_forwarder_for_vmware-<version>-<build_number>.zip in the downloaded VMware app package

Upgrade the data collection node

  1. Stop Splunk
  2. Install splunk_forwarder_for_vmware-<version>-<build_number>.zip
  3. Unzip this file (the data collection node components) from $SPLUNK_HOME
  4. Note: Make sure you unzip the package from $SPLUNK_HOME, not $SPLUNK_HOME/etc/apps
  5. Check that the data collection components SA-Utils, SA-Hydra, Splunk_TA_vmware, and Splunk_TA_esxilogs exist in $SPLUNK_HOME/etc/apps
  6. Delete the file $SPLUNK_HOME/etc/apps/Splunk_TA_vmware/local/hydra_job.conf
  7. Start Splunk

If the scheduler is not connecting to the new DCN for some reason,
1. please check versions of SA-Utils and SA-Hydra for both SH and DCN and make sure they are same.
2. Also, please try, delete the DCN from Configuration Collections and add it back.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...