<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Upgrade in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755057#M23396</link>
    <description>&lt;P&gt;what should be sequence for upgrading? could you suggest the precautions to be taken which may overcome the risk as I am doing this upgrade for the first time.&lt;/P&gt;</description>
    <pubDate>Sun, 02 Nov 2025 08:25:32 GMT</pubDate>
    <dc:creator>maheshnc</dc:creator>
    <dc:date>2025-11-02T08:25:32Z</dc:date>
    <item>
      <title>Splunk Upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755052#M23394</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I am new as splunk administrator here in the company.&amp;nbsp; we are using Splunk enterprise and the current version is &lt;STRONG&gt;9.2.4&lt;/STRONG&gt;, and as per splunk document this version is supported until &lt;STRONG&gt;Jan 31&lt;/STRONG&gt; &lt;STRONG&gt;2026&lt;/STRONG&gt;, can somebody guide me on&amp;nbsp; version upgrade, and also which version should we upgrade? Also, I am not sure about the risk in upgrading the version, please provide your suggestions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Nov 2025 16:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755052#M23394</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-11-01T16:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755053#M23395</link>
      <description>&lt;P&gt;For instructions on how to upgrade Splunk Enterprise, read the fine manual at&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/9.4/upgrade-or-migrate-splunk-enterprise/how-to-upgrade-splunk-enterprise" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/9.4/upgrade-or-migrate-splunk-enterprise/how-to-upgrade-splunk-enterprise&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The choice of which version to install is yours.&amp;nbsp; I recommend a later version of 9.4.x.&amp;nbsp; This will help you prepare for Splunk 10 without the risk of the same.&lt;/P&gt;&lt;P&gt;IMO, the risk of upgrading usually is less than that of not upgrading and being on an unsupported version.&amp;nbsp; Splunk 10 is an exception since it contains many breaking changes for which careful planning is recommended.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Nov 2025 17:21:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755053#M23395</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-11-01T17:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755057#M23396</link>
      <description>&lt;P&gt;what should be sequence for upgrading? could you suggest the precautions to be taken which may overcome the risk as I am doing this upgrade for the first time.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 08:25:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755057#M23396</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-11-02T08:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755058#M23397</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please refer this url&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Installation/What-s-the-order-of-operations-for-upgrading-Splunk-Enterprise/m-p/408003" target="_blank"&gt;https://community.splunk.com/t5/Installation/What-s-the-order-of-operations-for-upgrading-Splunk-Enterprise/m-p/408003&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 08:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755058#M23397</guid>
      <dc:creator>thahir</dc:creator>
      <dc:date>2025-11-02T08:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755059#M23398</link>
      <description>&lt;P&gt;Could you let me know about the version compatibility for various instances, I mean can we indexers, search heads and Heavy forwarders with different versions or should they have the same version?&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 09:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755059#M23398</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-11-02T09:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755060#M23399</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&lt;/P&gt;&lt;DIV&gt;Yes, ideally all your Splunk components—indexers, search heads, deployers, cluster managers, and heavy forwarders—should run the same version and its recommended from Splunk.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Refer the below URL for Compatibility matrix: &lt;A href="https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/compatibility-matrix/splunk-products-version-compatibility/splunk-products-version-compatibility-matrix" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/compatibility-matrix/splunk-products-version-compatibility/splunk-products-version-compatibility-matrix&lt;/A&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;For forwarders (both Universal and Heavy), Splunk officially supports a compatibility window where forwarders can be up to two major versions older than your indexers. You can find Splunk’s detailed compatibility guidelines at the official documentation link you referenced, which covers all combinations and exceptional scenarios.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;refer the below url: &lt;A href="https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/compatibility-matrix/splunk-products-version-compatibility/compatibility-between-forwarders-and-splunk-enterprise-indexers" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/compatibility-matrix/splunk-products-version-compatibility/compatibility-between-forwarders-and-splunk-enterprise-indexers&lt;/A&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;High Level upgrade plan&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;-&amp;gt; Pre check&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Apps/TA compatibility with the new version which you going to upgrade&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Backup the Splunk etc folder, certs and KV store&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;-&amp;gt; follow the upgrade sequence order&lt;/DIV&gt;&lt;DIV&gt;-&amp;gt; Post upgrade: verify the cluster health and review the splunkd logs, if you have DMC in your infra go through the&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; console and do the health check&lt;/DIV&gt;</description>
      <pubDate>Sun, 02 Nov 2025 09:36:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755060#M23399</guid>
      <dc:creator>thahir</dc:creator>
      <dc:date>2025-11-02T09:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755068#M23400</link>
      <description>&lt;P&gt;Could you please walk me through the backups needs to be taken/mandatory&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 06:24:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755068#M23400</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-11-03T06:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755078#M23401</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;, Backup the entire $SPLUNK_HOME/etc/ directory. basically it will cover all of your config related files.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 07:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755078#M23401</guid>
      <dc:creator>thahir</dc:creator>
      <dc:date>2025-11-03T07:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755087#M23406</link>
      <description>&lt;P&gt;Ideally, in a supported environment, all "main" components should be in the same version. You can get away with HFs running older versions (which is sometimes required if you have legacy systems for which you are using some legacy apps).&lt;/P&gt;&lt;P&gt;The order of upgrade can be deduced from the Installation Manual (and is charted in the post referenced somewhere else in this thread) but it can get tricky if your components have multiple roles.&lt;/P&gt;&lt;P&gt;Don't get me wrong but if you don't know nothing about upgrading Splunk and don't even know how to make a backup copy, maybe it's time to engage your local friendly Splunk Partner for this one and in the meanwhile set up a lab environment and train there before going all-in into the prod.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 11:11:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755087#M23406</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-11-03T11:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755129#M23412</link>
      <description>Additional to other instructions, here is Splunk's best practice documentation for upgrade &lt;A href="https://lantern.splunk.com/Manage_Performance_and_Health/Upgrading_the_Splunk_platform" target="_blank"&gt;https://lantern.splunk.com/Manage_Performance_and_Health/Upgrading_the_Splunk_platform&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Nov 2025 17:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Upgrade/m-p/755129#M23412</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-11-03T17:53:21Z</dc:date>
    </item>
  </channel>
</rss>

