Skip to content

Upgrade the Splunk Add-on for Cisco ISE

Upgrade from version 4.2.0 to version 5.0.0

Upgrade from Splunk Add-on for Cisco ISE version 4.2.0 to v5.0.0 requires no additional steps to be performed.

Upgrade from version 4.1.0 to version 4.2.0

Upgrade from Splunk Add-on for Cisco ISE version 4.1.0 to version 4.2.0 requires no additional steps to be performed.

Upgrade from version 4.0.0 to version 4.1.0

Upgrade from Splunk Add-on for Cisco ISE version 4.0.0 to version 4.1.0 requires no additional steps to be performed.

Upgrade an indexer cluster from Splunk Add-on for Cisco ISE version 3.0.0

  1. On the cluster master of your indexer cluster Splunk platform deployment, navigate to $SPLUNK_HOME/etc/master-apps/Splunk_TA_cisco-ise/local/.
  2. Open props.conf and edit the cisco:ise stanza to remove the following line:

    DATETIME_CONFIG = /etc/slave-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml

  3. Edit the cisco:ise:syslog stanza to remove the following line:

    DATETIME_CONFIG = /etc/slave-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml

  4. Save your changes.

  5. Push the configurations to your peer nodes.