Splunk Search

Upgrading apps in a clustered environment

mwdbhyat
Builder

When upgrading an app in a clustered environment (in this case the netflow analytics) - can I just update the folders and push it out via deployer, or will it delete any local config ?

Thanks !

0 Karma
1 Solution

NetFlow_Logic
Contributor

Starting with release 3.7, NetFlow Analytics for Splunk App and Technology Add-On for NetFlow, have index=flowintegrator and input UDP port 10514 not configured by default (Splunk certification requirement), so you have to create inputs.conf, indexes.conf, and macros.conf in local folders. Please see "Upgrading from prior version to 3.7" section for details in NetFlow Analytics for Splunk User Manual https://www.netflowlogic.com/wp-content/uploads/2017/02/NetFlow_Analytics_for_Splunk_User_Manual_3.7...

View solution in original post

0 Karma

NetFlow_Logic
Contributor

Starting with release 3.7, NetFlow Analytics for Splunk App and Technology Add-On for NetFlow, have index=flowintegrator and input UDP port 10514 not configured by default (Splunk certification requirement), so you have to create inputs.conf, indexes.conf, and macros.conf in local folders. Please see "Upgrading from prior version to 3.7" section for details in NetFlow Analytics for Splunk User Manual https://www.netflowlogic.com/wp-content/uploads/2017/02/NetFlow_Analytics_for_Splunk_User_Manual_3.7...

0 Karma

woodcock
Esteemed Legend

Do whatever you did the first time that you deployed it and make sure you make a back up first, just in case.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...