Splunk
Standalone Search Head
- Install the provided .spl using the Web GUI or the CLI.
- Configure Cribl Stream instances and collectors using the configuration dashboards
Search Head Cluster
- Unpack the provided .spl to $SPLUNK_HOME/etc/shcluster/apps on the deployer
- Deploy the app bundle to the search head cluster
- Configure Cribl Stream instances and collectors using the configuration dashboards
Upgrade from UTStream 1.0.0
On-Premise Splunk Enterprise
- Update UTStream to 2.0.0
- Move local/cribl_instance.conftolocal/utstream_instance.conf
- Add cribl_rolesto each stanza inlocal/utstream_instance.conf
- Add entries to local/passwords.conffor each instance using the following API call:No further action is required in case of acurl -k -u <username>:<password> https://localhost:8089/servicesNS/nobody/SA-DP-utstream/storage/passwords -d name=<username> -d password=<password> -d realm=<instance_name>A password already existserror.
- Restart Splunk
Splunk Cloud
As it is not possible to rename files in Splunk Cloud an upgrade is not possible. Please uninstall UTStream 1.0.0 and install UTStream 2.0.0.