Installation

Upgrade Splunk ESCU on Search head clsuter members

vikas_gopal
Builder

Hi Experts , 

Someone has installed ESCU app directly on the Search head members . Now I am upgrading this app to a newer release . 

Question :- Since this app was not installed from the deployer but I want to upgrade it via deployer what is the best practice and method to achieve this 

Here is my plan , please correct me if I am thinking wrong 

Step 1) First I will copy the installed folder from one of the SHC member to deployer under /etc/app so that it install itself on the deployer and then I can manually upgrade it using deployer GUI

Step2) Once upgraded , I will copy upgraded app from /etc/apps folder to /etc/shcluster/apps folder 

Step3) run apply shcluster-bundle on the deployer to push the upgraded app to SHC members .

Do you think above is the right approach ? if not what else I can do 

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @vikas_gopal ,

only one detail:

for my knowledge, the only app that requires to be installed on the SHC-Deployer is Splunk Enterprise Security,

all the other apps (so also ESCU) don't require to be installed in the SHC-Deployer, you can only copy and untar them in the $SPLUNK_HOME/etc/shcluster folder and then push them to the SHC memebers.

In genetal, avoid to install an app directly on a SH member.

Ciao.

Giuseppe

0 Karma

tej57
Contributor

Hello @vikas_gopal,

Yes, the steps you have mentioned seems to be the appropriate to continue managing the app from SHC Deployer in future. 

Thanks,
Tejas. 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...