Installation

Large Deployment Upgrading to 6.0

ShaneNewman
Motivator

I manage a fairly large deployment of Splunk for a healthcare organization. We recently merged 3 separate deployments into a single larger deployment (nix, windows, and firewall). Both the nix and windows deployments are still on 5.0.5. The firewall team, who use ping federate, are already on 6.0. Additionally, our security group recently purchased a 2.5TB license and wants my groups assistance in managing their deployment and maintaining their infrastructure.

We currently have over 300 active business users, running between 1000-3000 searches per day. All of these searches are powering 30 dashboards in advanced XML. With the addition of the security team's needs, we estimate searches being around 5,000 per day.

I have been told that advanced XML is depreciated in 6.0. With so many business users being impacted if this is the case, I am hesitant to make the switch. I know that our current dashboards work fine in our QA environment with advanced XML. Is there something I am missing? From what I have read on the forums and the documentation I only see that advanced XML is impacted when using some of the new features in 6.0, such as the pivot table feature.

Is this truly the case or have I missed something completely?

Preferably, we would hire Splunk to come in and do an evaluation of this. There is just no funds for that sort of project until second quarter of next year at the earliest. The mandate given to me by leadership has been to upgrade by the end of November at the latest.

0 Karma
1 Solution

nfilippi_splunk
Splunk Employee
Splunk Employee

Advanced XML has not yet been deprecated as of Splunk 6.

While advanced xml has not been deprecated in Splunk 6, it is encouraged that for further dashboard development, you leverage many of the new enhancements in this release around Simple XML, custom HTML, and django bindings.

For examples of some of the new enhancements and functionality around dashboard development, check out the following apps:

Splunk Enterprise 6 Dashboard Examples
http://apps.splunk.com/app/1603/

Splunk Web Framework Toolkit
http://apps.splunk.com/app/1613/

View solution in original post

nfilippi_splunk
Splunk Employee
Splunk Employee

Advanced XML has not yet been deprecated as of Splunk 6.

While advanced xml has not been deprecated in Splunk 6, it is encouraged that for further dashboard development, you leverage many of the new enhancements in this release around Simple XML, custom HTML, and django bindings.

For examples of some of the new enhancements and functionality around dashboard development, check out the following apps:

Splunk Enterprise 6 Dashboard Examples
http://apps.splunk.com/app/1603/

Splunk Web Framework Toolkit
http://apps.splunk.com/app/1613/

ChrisG
Splunk Employee
Splunk Employee

rakesh - that's a good question but you'd be better off posting it as a new question rather than a comment on this one.

0 Karma

rakesh_498115
Motivator

Hi nfillppi_splunk , one of the challenge we are facing with simple xml is , we are unable to put the excel_export option in simple xml ? is there any way to include this in simple xml pls ?

ShaneNewman
Motivator

There are several dashboard that will have to be completely redesigned to go forward using only simple xml and the rest. We have that in our scope of work for next year. I am just tying to make sure that for immediate needs I have not overlooked anything that would cripple our end users and force us to do a roll-back.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...