Installation
Initial Installation
Standalone Search Head
- Install the provided
.spl
using the Web GUI or the CLI. - Configure Elasticsearch instances and queries using the provided dashboards
Search Head Cluster
- Unpack the provided
.spl
to$SPLUNK_HOME/etc/shcluster/apps
on the deployer - Deploy the app bundle to the search head cluster
- Configure Elasticsearch instances and queries using one of the search head cluster members
Upgrade from 1.0.0
Due to minor changes in the configuration format, the upgrade process is a bit more involved. The following steps are required:
- Create a backup of the app's configuration files in
$SPLUNK_HOME/etc/apps/SA-DP-elasticspl/local
- Remove all configured instances through the Web GUI
- Install the new version of the app using the Web GUI or the CLI
- Reconfigure Elasticsearch instances using the provided dashboard