Install and Upgrade the Cisco Security Cloud App

Installation Overview

The Cisco Security Cloud App for Splunk can be deployed in either a single-instance or distributed Splunk environment:

  • Single-instance deployment: The app runs on a single system that handles all roles—such as indexer, search head, and forwarder.

  • Distributed deployment: Roles are distributed across multiple systems (for example, separate indexers and search heads). In this setup, you must install the app on the search heads.

You can install the app in one of the following ways:

  • Install from a package

  • Install from Splunkbase

Prerequisites

Ensure these prerequisites are met before installing or upgrading the app:

Install Cisco Security Cloud App from a Package

Procedure


Step 1

Download Security Cloud App from the Splunkbase:https://splunkbase.splunk.com/app/7404.

Step 2

Click Manage to navigate to the Apps page.

Step 3

On the Apps page, click Install app from file.

Step 4

In the Install App From File window, choose the file (Security Cloud App) that you downloaded and click Upload.

Step 5

After the installation is complete, verify that the Cisco Security Cloud app is listed on the Apps page.


Install Cisco Security Cloud App from Splunkbase

Procedure


Step 1

Log in to Splunkbase using your administrator credentials.

Step 2

Click Manage to navigate to the Apps page.

Step 3

On the Apps page, click Browse more apps.

Step 4

Search for Security Cloud App in the search bar.

Step 5

On the Security Cloud App card, click Install.

Step 6

Enter your Splunk credentials in the Login and Install window. Review the terms and conditions and click Agree and Install.

Step 7

After the installation complete, click Open the App.

Step 8

You are redirected to the Application Setup page of Security Cloud App.


Upgrade Cisco Security Cloud App

Upgrade from a major release to another major release

Follow these steps to upgrade the Cisco Security Cloud App from a major release to another major release:

Procedure


Step 1

Uninstall the current release of the app.

Step 2

Clear the browser cache and cookies.

Step 3

Install the newer release of the app using one of the two methods described earlier - Install the app from file or Install the app from Splunkbase.

Step 4

Restart Splunk by navigating to Splunk > Settings > Server Controls > Restart Splunk.


Upgrade from a minor release to another minor release

Follow these steps to upgrade the Cisco Security Cloud App from a minor release to another minor release (For example, upgrade from release x.1.x to x.2.x release)

Procedure


Step 1

Clear the browser cache and cookies.

Step 2

Install the newer release of the app using one of the two methods described earlier - Install the app from file or Install the app from Splunkbase.

Step 3

Restart Splunk. Navigate to Splunk > Settings > Server Controls > Restart Splunk.