<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Considerations to upgrade from Enterprise 9.1.1 to 9.4.2 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747158#M22328</link>
    <description>&lt;P&gt;"Thanks a lot for the detailed info — I really appreciate it! I'm fully on board and diving into it. Great to have your attention on this. By the way, the DS server is running on Linux."&lt;/P&gt;</description>
    <pubDate>Thu, 29 May 2025 01:39:05 GMT</pubDate>
    <dc:creator>heres1</dc:creator>
    <dc:date>2025-05-29T01:39:05Z</dc:date>
    <item>
      <title>Considerations to upgrade from Enterprise 9.1.1 to 9.4.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747031#M22323</link>
      <description>&lt;P&gt;Considerations to upgrade from Enterprise 9.1.1 to 9.4.2,&amp;nbsp; while its also a deployment server.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 19:40:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747031#M22323</guid>
      <dc:creator>heres1</dc:creator>
      <dc:date>2025-05-27T19:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Considerations to upgrade from Enterprise 9.1.1 to 9.4.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747037#M22325</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310490"&gt;@heres1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Confirmed by&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/Installation/HowtoupgradeSplunk#:~:text=and%20release%20notes.-,Upgrade%20paths%20to%20version%209.4,-The%20following%20table" target="_self"&gt;the docs&lt;/A&gt;, there is no need to upgrade to an intermediate version - you can upgrade directly from 9.1.x to 9.4.x.&lt;/P&gt;&lt;P&gt;There are quite a few differences between 9.1.1 and 9.4.2 so I rather than me listing them all here, I'd recommend having a read through&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/Installation/AboutupgradingREADTHISFIRST" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.2/Installation/AboutupgradingREADTHISFIRST&lt;/A&gt;&amp;nbsp;as there may be other changes/feature deprecations that you rely on.&lt;/P&gt;&lt;P&gt;Most notably is probably KVStore upgrades, SSL changes but there are also some big Deployment Server changes, therefore its also worth reading&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Updating/Upgradepre-9.2deploymentservers" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Updating/Upgradepre-9.2deploymentservers&lt;/A&gt;&amp;nbsp;which details some of the changes and possible configuration changes you may have to make around your log forwarding on your DS in order to retain the visibility of the Forwarder Managment / Agent Manager section.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you running Linux or Windows? Im not sure of specific changes for either but happy to review this.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 20:52:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747037#M22325</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-27T20:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Considerations to upgrade from Enterprise 9.1.1 to 9.4.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747039#M22326</link>
      <description>&lt;P&gt;Regarding the DS specifically, have a good read of&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Updating/Upgradepre-9.2deploymentservers" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Updating/Upgradepre-9.2deploymentservers&lt;/A&gt;&amp;nbsp;but essentially you need to make sure that your indexers have the relevant DS indexes created as the phone-home and other deployment data is now held here:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;== indexes ==
[_dsphonehome]
[_dsclient]
[_dsappevent]&lt;/LI-CODE&gt;&lt;P&gt;and also configure the outputs.conf to ensure that the data is saved locally on the DS too (so it can display the client info!)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;== outputs.conf ==
[indexAndForward]
index = true
selectiveIndexing = true     &lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 21:12:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747039#M22326</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-27T21:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Considerations to upgrade from Enterprise 9.1.1 to 9.4.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747158#M22328</link>
      <description>&lt;P&gt;"Thanks a lot for the detailed info — I really appreciate it! I'm fully on board and diving into it. Great to have your attention on this. By the way, the DS server is running on Linux."&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 01:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747158#M22328</guid>
      <dc:creator>heres1</dc:creator>
      <dc:date>2025-05-29T01:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Considerations to upgrade from Enterprise 9.1.1 to 9.4.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747696#M22366</link>
      <description>&lt;P&gt;Thanks for your previous guidance.&lt;/P&gt;&lt;P&gt;I've retried the process and made a full backup of both /opt/splunk/etc and /opt/splunk/var just in case. I then proceeded with a clean reinstallation of Splunk Enterprise version 9.4.3.&lt;/P&gt;&lt;P&gt;Everything seems to be working fine except for the KV Store, which is failing to start.&lt;/P&gt;&lt;P&gt;Upon investigation, I found that the version used previously (4.0.x) is no longer compatible with Splunk 9.4.3, which likely makes my backup of the KV Store unusable under the new version.&lt;/P&gt;&lt;P&gt;Additionally, even after the KV Store upgrade attempt, my Universal Forwarders still do not appear in the Forwarder Management view, even though they are actively sending data and I can see established TCP connections on port 9997.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jun 2025 16:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Considerations-to-upgrade-from-Enterprise-9-1-1-to-9-4-2/m-p/747696#M22366</guid>
      <dc:creator>heres1</dc:creator>
      <dc:date>2025-06-09T16:20:18Z</dc:date>
    </item>
  </channel>
</rss>

