<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Server Update in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618107#M14303</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Here is some old answers, how to upgrade splunk from one version to another.&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Installation/Upgrading-and-migrating-to-a-new-host-how-to-migrate-large/m-p/601048#M11615" target="_blank"&gt;https://community.splunk.com/t5/Installation/Upgrading-and-migrating-to-a-new-host-how-to-migrate-large/m-p/601048#M11615&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Installation/How-to-migrate-indexes-to-new-indexer-instance/m-p/528001" target="_blank"&gt;https://community.splunk.com/t5/Installation/How-to-migrate-indexes-to-new-indexer-instance/m-p/528001&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Basically you can do it on same box, but if you want to refresh HW / OS at same time then you should follow above answer.&lt;/P&gt;&lt;P&gt;One thing which you must check when you are upgrading from 8.x to 9.0 is python and another mongodb. There are also some other security stuff changes which are described on Splunk's security guide.&lt;/P&gt;&lt;P&gt;8.1 python 2 is default (3 option), 8.2. it can by 2 or 3 (default) and in 9.0 there is only python3 left. This means that all TAs / Apps etc. must work with python3.&lt;/P&gt;&lt;P&gt;Mongodb will be updated to TigerShak and also engine version will be updated. But in single node environment that should handled automatic when you are doing upgrade.&lt;/P&gt;&lt;P&gt;Otherwise your plan seems to be ok.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Mon, 24 Oct 2022 07:03:19 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-10-24T07:03:19Z</dc:date>
    <item>
      <title>Splunk Server Update- Is it possible to restore backup file version 8.2 directly to 9.0?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618096#M14300</link>
      <description>&lt;P&gt;Hello all, I have a Splunk server update.&lt;BR /&gt;We have an update to our Splunk server and I am trying to figure out the workflow.&lt;BR /&gt;Current version 8.2.&lt;BR /&gt;The new server is 9.0.&lt;/P&gt;
&lt;P&gt;I want to restore the backup files of the current version 8.2 to the new server version 9.0.&lt;BR /&gt;Is it possible to restore the backup file of version 8.2 directly to version 9.0?&lt;BR /&gt;Or, is it necessary to build a new device with version 8.2, restore it, and then upgrade to version 9.0?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 13:22:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618096#M14300</guid>
      <dc:creator>yoshi99</dc:creator>
      <dc:date>2022-10-24T13:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Server Update</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618099#M14301</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196522"&gt;@yoshi99&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For How many servers are you trying to Upgrade Splunk Version to 9?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;if it a single server, you can take a backup of&amp;nbsp;&lt;SPAN&gt;$SPLUNK_HOME/etc/ and restore them directly on version 9&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/HowtoupgradeSplunk#Splunk_Enterprise_upgrade_process" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/HowtoupgradeSplunk#Splunk_Enterprise_upgrade_process&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if it is clustered envieromenet , you &lt;STRONG&gt;need to upgrade the severs based on Splunk components&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;please upgrade in following order(which I folllowed when we upraded the infra)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;1.Clustmaster&amp;nbsp;&lt;BR /&gt;2.License Master&lt;BR /&gt;3.Search Head&lt;BR /&gt;4.Indexers (enable cluster master in maintenance&amp;nbsp;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;5. Deployment server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;6. forwarders&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;for deatrlied steps for indexer upgrade please refer to&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Indexer/Upgradeacluster" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Indexer/Upgradeacluster&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;also please go throuth the following docs&amp;nbsp; before you upgarde to 9.0&amp;nbsp; and for upgrade related info&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/AboutupgradingREADTHISFIRST" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/AboutupgradingREADTHISFIRST&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/HowtoupgradeSplunk" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/HowtoupgradeSplunk&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Sanjay Reddy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;---&lt;BR /&gt;If this reply helps you, Karma would be appreciated.&lt;/P&gt;&lt;P&gt;If your problem is resolved, then please click the "Accept as Solution" button to help future readers.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 05:00:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618099#M14301</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2022-10-24T05:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Server Update</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618102#M14302</link>
      <description>&lt;P&gt;Hi Sanjay Reddy&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;BR /&gt;Your answers have been very helpful.&lt;/P&gt;&lt;P&gt;We have only one Splunk server.&lt;/P&gt;&lt;P&gt;Please let me check additionally.&lt;/P&gt;&lt;P&gt;I found that the configuration file can be restored from Version 8.x to Version 9.x. Can the database be restored as well? Can the database be restored as well?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;-Procedure&lt;/P&gt;&lt;P&gt;-Version 8.x backup (old Splunk server)&lt;BR /&gt;Backup with Splunk service stopped.&lt;/P&gt;&lt;P&gt;Backup $SPLUNK_HOME/etc/ for configuration.&lt;BR /&gt;Backup $SPLUNK_HOME/var/lib/splunk/defaultdb for index database.&lt;BR /&gt;Backup other index databases as needed.&lt;/P&gt;&lt;P&gt;-Ver9.x restore (new Splunk server)&lt;BR /&gt;Restore with Splunk service stopped.&lt;BR /&gt;Restore configuration to $SPLUNK_HOME/etc/.&lt;BR /&gt;Index database is restored to $SPLUNK_HOME/var/lib/splunk/defaultdb.&lt;BR /&gt;&lt;BR /&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 05:23:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618102#M14302</guid>
      <dc:creator>yoshi99</dc:creator>
      <dc:date>2022-10-24T05:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Server Update</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618107#M14303</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Here is some old answers, how to upgrade splunk from one version to another.&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Installation/Upgrading-and-migrating-to-a-new-host-how-to-migrate-large/m-p/601048#M11615" target="_blank"&gt;https://community.splunk.com/t5/Installation/Upgrading-and-migrating-to-a-new-host-how-to-migrate-large/m-p/601048#M11615&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Installation/How-to-migrate-indexes-to-new-indexer-instance/m-p/528001" target="_blank"&gt;https://community.splunk.com/t5/Installation/How-to-migrate-indexes-to-new-indexer-instance/m-p/528001&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Basically you can do it on same box, but if you want to refresh HW / OS at same time then you should follow above answer.&lt;/P&gt;&lt;P&gt;One thing which you must check when you are upgrading from 8.x to 9.0 is python and another mongodb. There are also some other security stuff changes which are described on Splunk's security guide.&lt;/P&gt;&lt;P&gt;8.1 python 2 is default (3 option), 8.2. it can by 2 or 3 (default) and in 9.0 there is only python3 left. This means that all TAs / Apps etc. must work with python3.&lt;/P&gt;&lt;P&gt;Mongodb will be updated to TigerShak and also engine version will be updated. But in single node environment that should handled automatic when you are doing upgrade.&lt;/P&gt;&lt;P&gt;Otherwise your plan seems to be ok.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 07:03:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618107#M14303</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-10-24T07:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Server Update</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618124#M14305</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your kind words.&lt;/P&gt;&lt;P&gt;First, I will create an environment and evaluate it.&lt;BR /&gt;It seems like a good idea to check.&lt;/P&gt;&lt;P&gt;If I have any trouble, I would like to get advice from you all.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 09:33:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Server-Update-Is-it-possible-to-restore-backup-file/m-p/618124#M14305</guid>
      <dc:creator>yoshi99</dc:creator>
      <dc:date>2022-10-24T09:33:12Z</dc:date>
    </item>
  </channel>
</rss>

