Skip to content

Upgrade the Splunk Add-on for Cisco ISE

Upgrade from v4.1.0 to v4.2.0

Upgrade from Splunk Add-on for Cisco ISE v4.1.0 to v4.2.0 requires no additional steps to be performed.

Upgrade from v4.0.0 to v4.1.0

Upgrade from Splunk Add-on for Cisco ISE v4.0.0 to v4.1.0 requires no additional steps to be performed.

Upgrade an indexer cluster from Splunk Add-on for Cisco ISE version 3.0.0

  1. On the cluster master of your indexer cluster Splunk platform deployment, navigate to $SPLUNK_HOME/etc/master-apps/Splunk_TA_cisco-ise/local/.
  2. Open props.conf and edit the cisco:ise stanza to remove the following line:

    DATETIME_CONFIG = /etc/slave-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml
    
  3. Edit the cisco:ise:syslog stanza to remove the following line:

    DATETIME_CONFIG = /etc/slave-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml
    
  4. Save your changes.

  5. Push the configurations to your peer nodes.