<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Server OS Security patching in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Server-OS-Security-patching/m-p/753595#M29707</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;General best practices are,&lt;/P&gt;&lt;P&gt;Backups &amp;amp; Config Safety first&lt;BR /&gt;-Back up $SPLUNK_HOME/etc (configs, apps, knowledge objects).&lt;BR /&gt;-Back up critical KV Store collections&lt;BR /&gt;-VM snapshots or system‑level backups in case rollback is needed.&lt;/P&gt;&lt;P&gt;For Indexer Cluster:&lt;BR /&gt;-Put the cluster into maintenance mode.&lt;BR /&gt;-Better patch one peer at a time.&lt;/P&gt;&lt;P&gt;Post Checks&lt;BR /&gt;Service Validation&lt;BR /&gt;-Confirm Splunk service is running&lt;BR /&gt;-Verify web UI(Applicable ones) and CLI access&lt;/P&gt;&lt;P&gt;Cluster Health&lt;BR /&gt;-Indexer Cluster - all peers should be Up and In‑Sync.&lt;BR /&gt;-SHC - all members should be Up and Ready&lt;BR /&gt;-Disable maintenance mode once all peers are patched&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Data Flow&lt;BR /&gt;-Perform simple searches (index=YOUR_INDEX | head 5) to confirm indexing is happening.&lt;BR /&gt;-Check forwarders are still connected (Settings → Forwarder Management)&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 25 Sep 2025 07:03:57 GMT</pubDate>
    <dc:creator>PrewinThomas</dc:creator>
    <dc:date>2025-09-25T07:03:57Z</dc:date>
    <item>
      <title>Splunk Server OS Security patching</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Server-OS-Security-patching/m-p/753593#M29706</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Our operations team is supposed to perform&amp;nbsp;OS Security patching on indexer cluster, search head, Heavy Forwarders, deployment server and licence master, I want to know, as a Splunk admin what are the prechecks and post-checks need to be performed? for example, do we need to take backup etc.&lt;BR /&gt;&lt;BR /&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 06:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Server-OS-Security-patching/m-p/753593#M29706</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-09-25T06:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Server OS Security patching</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Server-OS-Security-patching/m-p/753595#M29707</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;General best practices are,&lt;/P&gt;&lt;P&gt;Backups &amp;amp; Config Safety first&lt;BR /&gt;-Back up $SPLUNK_HOME/etc (configs, apps, knowledge objects).&lt;BR /&gt;-Back up critical KV Store collections&lt;BR /&gt;-VM snapshots or system‑level backups in case rollback is needed.&lt;/P&gt;&lt;P&gt;For Indexer Cluster:&lt;BR /&gt;-Put the cluster into maintenance mode.&lt;BR /&gt;-Better patch one peer at a time.&lt;/P&gt;&lt;P&gt;Post Checks&lt;BR /&gt;Service Validation&lt;BR /&gt;-Confirm Splunk service is running&lt;BR /&gt;-Verify web UI(Applicable ones) and CLI access&lt;/P&gt;&lt;P&gt;Cluster Health&lt;BR /&gt;-Indexer Cluster - all peers should be Up and In‑Sync.&lt;BR /&gt;-SHC - all members should be Up and Ready&lt;BR /&gt;-Disable maintenance mode once all peers are patched&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Data Flow&lt;BR /&gt;-Perform simple searches (index=YOUR_INDEX | head 5) to confirm indexing is happening.&lt;BR /&gt;-Check forwarders are still connected (Settings → Forwarder Management)&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 07:03:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Server-OS-Security-patching/m-p/753595#M29707</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-09-25T07:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Server OS Security patching</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Server-OS-Security-patching/m-p/753596#M29708</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition to the other steps, make sure to back up the /opt/splunk/bin directory on the Heavy Forwarders. If any custom scripts were placed directly in /opt/splunk/bin, it’s essential to include this directory in your pre-patching backup.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 07:30:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Server-OS-Security-patching/m-p/753596#M29708</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-09-25T07:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Server OS Security patching</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Server-OS-Security-patching/m-p/753607#M29709</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 11:08:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Server-OS-Security-patching/m-p/753607#M29709</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-09-25T11:08:24Z</dc:date>
    </item>
  </channel>
</rss>

