<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk server OS patching in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426121#M7943</link>
    <description>&lt;P&gt;can we offline two to three splunk instances and upgrade the OS at once ?? &lt;BR /&gt;
Or is it mandatory to offline only one instance at a time ?? &lt;/P&gt;</description>
    <pubDate>Thu, 24 Jan 2019 02:30:41 GMT</pubDate>
    <dc:creator>nawazns5038</dc:creator>
    <dc:date>2019-01-24T02:30:41Z</dc:date>
    <item>
      <title>Splunk server OS patching</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426120#M7942</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;I wish to patch the Linux OS for all the Splunk servers (including search heads, indexers etc). There are a lot of instances. &lt;BR /&gt;
IS there any specific procedure to be followed or just have to be patched one by one. &lt;BR /&gt;
Splunk version 6.5.3 &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 20:51:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426120#M7942</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2019-01-23T20:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk server OS patching</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426121#M7943</link>
      <description>&lt;P&gt;can we offline two to three splunk instances and upgrade the OS at once ?? &lt;BR /&gt;
Or is it mandatory to offline only one instance at a time ?? &lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 02:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426121#M7943</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2019-01-24T02:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk server OS patching</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426122#M7944</link>
      <description>&lt;P&gt;You should not have to interrupt the splunk or OS core services at all to upgrade, but it depends on your distribution.  It could be as simple as &lt;CODE&gt;yum upgrade&lt;/CODE&gt; wait, test, move to the next server, and so on.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 02:48:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426122#M7944</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-24T02:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk server OS patching</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426123#M7945</link>
      <description>&lt;P&gt;how about reboot after that. &lt;CODE&gt;yum upgrade&lt;/CODE&gt; requires  a reboot for sure in order to take effect of full updates.&lt;/P&gt;

&lt;P&gt;Can we reboot multiple Splunk indexers at least at once or should it only be individual ?  &lt;/P&gt;</description>
      <pubDate>Sun, 27 Jan 2019 00:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426123#M7945</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2019-01-27T00:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk server OS patching</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426124#M7946</link>
      <description>&lt;P&gt;If you are clustered, you can do a rolling restart from the CLI.  Otherwise, any indexer reboot is an outage so just do them all at once.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jan 2019 01:32:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426124#M7946</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-27T01:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk server OS patching</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426125#M7947</link>
      <description>&lt;P&gt;So what did you end up doing?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 05:40:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-server-OS-patching/m-p/426125#M7947</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-13T05:40:48Z</dc:date>
    </item>
  </channel>
</rss>

