Splunk Enterprise

Splunk App for Windows Infrastructure (Upgrade or New Installation)

SirDrake7
Explorer

Our Splunk environment appears to have been installed with the basic installation and just handed over to our development staff, who have done some amazing things with it for our application monitoring and such.  I recently noticed this and have upgraded it from 7.1 to 7.3 Enterprise and then to 8.1 Enterprise.  I also went in and upgraded the majority of the applications ensuring that I keep the majority on the app version that supported both 7.x and the new 8.x.  Our Splunk App for Windows Infrastructure is currently version 4.8.4 and research is telling me to upgrade to version 5.0 prior to moving on to version 7.  That is where my question comes in:

If I open up the app - it's at the Setup stage, meaning it docent even appear to have been installed.  If that is the case can I not just delete the version 4.8.4, and go directly to version 7 and set that up?  Or should I go to 5.0 and then up to make sure?  Is there anyway to verify?  Thanks for any advice - we are just a small shop (which may be why it was setup as it was), so starting fresh with a new install would be easier for me to understand but I don't want to take a short cut either and get burt.   

Setup the Splunk App for Windows Infrastructure

Prerequisites - Requirements for the app
Check Data - Verify data is coming into Splunk
Customize Features - Detect and choose which features to use

 

 

Splunk v7.2.0+

OK: Splunk v8.1.0 detected

OK: Key value store is enabled. Learn more.

 

 

Splunk Add-on for Microsoft Windows v7.0.0

Update required: v4.8.4 installed. It does not match with v7.0.0

 

Splunk Supporting Add-on for Microsoft Windows Active Directory v3.0.1

OK: Splunk Supporting Add-on for Microsoft Windows Active Directory v3.0.1 detected

 

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...