Upgrade the Splunk Add-on for Microsoft Office 365¶
Find the section that matches your currently installed version, and follow the linked procedure. If you’re on a version earlier than 4.1.0, complete Upgrade from a version earlier than 4.1.0 first, then continue with Upgrade from version 4.1.0.
If you’re seeing high memory usage while migrating Management Activity inputs: use the Facing high memory usage? procedure below instead of enabling all inputs at once.
Upgrade from version 4.2.0 or later¶
Worldwide Message Trace inputs
If you are upgrading from a version earlier than 6.0.0 and have Message Trace inputs for a Worldwide tenant, follow Update Message Trace inputs for the Splunk Add-on for Microsoft Office 365.
This path also covers upgrading to 5.x and 6.x releases.
- Download the latest version of Splunk Add-on for Microsoft Office 365 from Splunkbase.
- Install the add-on across your deployment.
- Verify that your inputs are enabled and resuming data collection as expected.
Note
- After upgrading the Splunk Add-on for Microsoft Office 365 to version 4.4.0, inputs created with the same name but different content-types, or any input with a name that begins with
_, cannot be edited. - Version 4.4.0 is not backward compatible and if you downgrade from version 4.3.0, downgrading will result in complete data duplication due to major checkpoint changes.
Upgrade from version 4.1.0¶
Note
After upgrading the Splunk Add-on for Microsoft Office 365 from version 4.0.0 or later to version 4.1.0 or later (including version 4.2.0 and higher), due to a change in checkpoint logic, your Splunk platform deployment might receive duplicate events for a maximum of 7 days. Duplicate events will stop ingesting after 7 days. You may observe a rise in the usage of your deployment’s memory/CPU resources. Restarting the Splunk platform or disabling an input during this 7-day window can cause additional duplication of management activity events the Splunk Add-on for Microsoft Office 365 is collecting at that time.
If the Splunk Add-on for Microsoft Office 365 was previously installed and configured, complete these steps before upgrading to version 4.1.0 or later.
- Disable all inputs.
- Download the latest version of Splunk Add-on for Microsoft Office 365 from Splunkbase.
- Install the add-on across your deployment.
- For existing tenants configured with a Cloud App Security Token, a warning appears prompting you to re-enter the tenant’s Cloud App Security Token. To resolve it, edit the tenant and re-enter the token. If submitting the new token fails with a validation error, delete the tenant by clicking Delete and reconfigure it.
- Enable all configured inputs to resume data collection.
Facing high memory usage?¶
If the Splunk Add-on for Microsoft Office 365 was previously installed and configured, complete these steps before upgrading to version 4.2.0 or later if you’re experiencing high memory usage:
- Disable all Management Activity Inputs.
- Download the latest version of Splunk Add-on for Microsoft Office 365 from Splunkbase.
- Install the add-on across your Splunk platform deployment.
- Enable one Management Activity input at a time, and confirm checkpoint migration for each input:
- Check for the
Checkpoint Migration Completed Successfullymessage in the UI. - Check for the
Completed KVStore Migration for Input: <input_name>message in the internal logs.
- Check for the
- Repeat the above steps until each management activity input has been migrated successfully.
Migration performance statistics¶
The following table shows performance statistics collected during this migration process for management activity inputs:
| Splunk Platform Version/Type | Memory | OS | Number of Inputs | Checkpoint Size Main Input (GB) | Checkpoint Size Other Input (individual) (GB) | Theoretical Memory Utilization (%) | Migration Time | CPU Utilization(AVG) | Memory Utilization(AVG) | KVStore Health Check | Migration Status | Additional Comments |
| 8.x(Enterprise) | VCPU 2 / 8 GB | Linux | 1 | 1.1 | 25 | Failed | At the time of migration, Memory Error when reading the checkpoint file. | |||||
| 9.x(Enterprise/Heavy Forwarder) | VCPU 2 / 8 GB | Linux | 2 | 0.5 | 0.7 | 65 | Input 1 : 24m 20s Input 1 : 32m 14s | ~45% | ~60% | Normal | Success | The migration process for both inputs ran in parallel. |
| 9.x(Enterprise) | VCPU 4 / 16 GB | Linux | 2 | 1.2 | 1.2 | 50 | Input 1: 53m 08s Input 2: 51m 28s | ~50% | ~50% | Normal | Success | The migration process for both inputs ran sequentially. |
| 9.x(Enterprise/Heavy Forwarder) | VCPU 8 / 32 GB | Linux | 3 | 1.3 | 1.3 | 30 | Input 1: 01h 05m 56s Input 2: 01h 02m 51s Input 3: 01h 05m 43s | ~45% | ~60% | Normal | Success | Started checkpoint migration for 2 input parallel and it was successful. |
| 8.x(Victoria) | VCPU 8 / 32 GB | Linux | 5 | 10 | 3 | 80 | Input 1: ~ 01h Input 2: ~ 01h Input 3: ~ 01h Input 4: ~ 45m Input 5: ~ 45m | Normal | Success | Started with 2 main inputs, then 3 inputs, and then the migration was complete. |
Upgrade from a version earlier than 4.1.0¶
If the Splunk Add-on for Microsoft Office 365 was previously installed and configured, complete these steps before upgrading to version 4.1.0 or later.
- Disable all inputs.
- Download the latest version of Splunk Add-on for Microsoft Office 365 from Splunkbase.
- Install the add-on across your deployment.
- Re-enter the tenant’s client secrets and proxy passwords. If an alert says Re-enter client secret before the Edit button, update all applicable tenants in your environment. If submitting a new secret fails because you’re also required to enter a Cloud Application Security Token, delete the tenant from your
splunk_ta_o365_tenants.conffile and create a new one. - Enable all configured inputs to resume data collection.
For Python 3 guidance on upgrading your Splunk Enterprise deployment to version 8.0.0 and later, see Choose your Splunk Enterprise upgrade path for the Python 3 migration in the Splunk Enterprise manual.