All Apps and Add-ons

What free App replaces "Splunk App for AWS" which goes EOL Jan5 2020?

radam2000
Path Finder

The doc mentions IT Essentials Work.
Tried to download IT Essentials work but I get an error message during installation.

"App Installation failed"
"invalid app contents: archive contains more than one immediate subdirectory: and DA-ITSI-DATABASE"

I still have the "Splunk add-on for amazon web services" version 5.1.0 running on a heavy forwarder collecting the data and sending it to my indexes on splunkcloud...   (5.2.0 is broken)


Labels (1)
Tags (1)
0 Karma

joshiro
Communicator

We are having the same issue with the message "There was an error processing the upload.Invalid app contents: archive contains more than one immediate subdirectory: and DA-ITSI-DATABASE"

Have you managed to install Essentials Work?

0 Karma

Wiessiet
Path Finder

EDIT: I just reread your post and I see you're already running the add-on for amazon web services; apologies. In that case I think you're on to the right application but I'm afraid I can't help with why the install is failing..

 

*Please* take this with a grain of salt as I'm a reasonably new Splunk administrator and still coming up to speed, but I went down this rabbit hole myself and perhaps this information will be useful to you. Best I can tell, IT Essentials Work is the free version of IT Service Intelligence (ITSI) - so if you see collision between the two they're basically the same, but one is free and one is as-a-service. Lots of different *visualization* and data interpretation applications are getting rolled into this, including Splunk App for AWS (https://splunkbase.splunk.com/app/1274/). This doesn't cover the *ingestion* layer though. What you probably want to look into is "Splunk Add-on for Amazon Web Services" (https://splunkbase.splunk.com/app/1876/). This is the ingestion layer application that would run on your forwarders and it is not deprecated like the other app.

radam2000
Path Finder

sorry couldn't figure out how to modify my post so replying - i meant EOL jan 5 2022

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...