<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Enterprise Upgrade in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunk-Enterprise-Upgrade/m-p/401146#M8771</link>
    <description>&lt;P&gt;Hi All,&lt;BR /&gt;
With regards to Splunk Enterprise I have the below query:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I have a existing Splunk infra that has Splunk Enterprise 6.5.3 running on all the servers. It has got all the apps TA-'s configured and they are running properly in PROD. environment&lt;/LI&gt;
&lt;LI&gt;Now, I have built a new infra (with new servers) and has got Splunk Enterprise 7.2.1 installed and configured on all the servers.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Our plan is to implement any new on-boarding of log feeds into new infra and going forward merge all the apps and TA-s that are currently running on the existing infra to the new Infra.&lt;/P&gt;

&lt;P&gt;We have 2 approaches to take it forward:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Migrate all the existing configurations related to app's and TA-s from the existing infra to new infra (Splunk 7.2.1)&lt;/LI&gt;
&lt;LI&gt;Else, upgrade the existing PROD. infra to Splunk 7.2.1 and then merge all the app's and TA-'s related to existing infra to the new infra that has already Splunk 7.2.1&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;So, kindly suggest which method I have to follow. If yes, then can you provide the reason for choosing the method (Justification)&lt;/P&gt;

&lt;P&gt;regards,&lt;BR /&gt;
Santosh&lt;/P&gt;</description>
    <pubDate>Tue, 19 Feb 2019 08:01:51 GMT</pubDate>
    <dc:creator>santosh_hb</dc:creator>
    <dc:date>2019-02-19T08:01:51Z</dc:date>
    <item>
      <title>Splunk Enterprise Upgrade</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Enterprise-Upgrade/m-p/401146#M8771</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;
With regards to Splunk Enterprise I have the below query:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I have a existing Splunk infra that has Splunk Enterprise 6.5.3 running on all the servers. It has got all the apps TA-'s configured and they are running properly in PROD. environment&lt;/LI&gt;
&lt;LI&gt;Now, I have built a new infra (with new servers) and has got Splunk Enterprise 7.2.1 installed and configured on all the servers.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Our plan is to implement any new on-boarding of log feeds into new infra and going forward merge all the apps and TA-s that are currently running on the existing infra to the new Infra.&lt;/P&gt;

&lt;P&gt;We have 2 approaches to take it forward:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Migrate all the existing configurations related to app's and TA-s from the existing infra to new infra (Splunk 7.2.1)&lt;/LI&gt;
&lt;LI&gt;Else, upgrade the existing PROD. infra to Splunk 7.2.1 and then merge all the app's and TA-'s related to existing infra to the new infra that has already Splunk 7.2.1&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;So, kindly suggest which method I have to follow. If yes, then can you provide the reason for choosing the method (Justification)&lt;/P&gt;

&lt;P&gt;regards,&lt;BR /&gt;
Santosh&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 08:01:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Enterprise-Upgrade/m-p/401146#M8771</guid>
      <dc:creator>santosh_hb</dc:creator>
      <dc:date>2019-02-19T08:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Upgrade</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Enterprise-Upgrade/m-p/401147#M8772</link>
      <description>&lt;P&gt;In my view, you can use either of the two approaches. Both will be fine. However, you would need to have a few considerations to decide.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;How many servers do you have in old and new infra? is there any clustering involved?&lt;/LI&gt;
&lt;LI&gt;what's your retention period for indexes? If its less than 6months, its better to use new infra as you can decommission the old infra [ adds costs till you decom them]. If you have a longer retention, upgrade will be better, as migrating buckets needs careful analysis and time consuming, should you run into bucket fixes/issues.&lt;/LI&gt;
&lt;LI&gt;As you have already built the new infra and have a plans to onboard new data and have a plan to migrate them to new infra, option 2(new infra) is better.&lt;/LI&gt;
&lt;LI&gt;what was the driving factor for building a new infra as opposed to upgrade? is that due to ageing hardware, timescales or need to on-board new data?&lt;/LI&gt;
&lt;LI&gt;Can your new infra provide a seamless interface or better one compared to old interface to users?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:58:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Enterprise-Upgrade/m-p/401147#M8772</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-02-22T16:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Upgrade</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Enterprise-Upgrade/m-p/401148#M8773</link>
      <description>&lt;P&gt;Hi @santosh_hb ,&lt;/P&gt;

&lt;P&gt;You can refer this link .&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.4/Installation/HowtoupgradeSplunk#Back_up_your_existing_deployment"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.4/Installation/HowtoupgradeSplunk#Back_up_your_existing_deployment&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;hope this helps you!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 17:39:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Enterprise-Upgrade/m-p/401148#M8773</guid>
      <dc:creator>vinod94</dc:creator>
      <dc:date>2019-02-22T17:39:36Z</dc:date>
    </item>
  </channel>
</rss>

