<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk ES Upgrade Compatibility in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480413#M7685</link>
    <description>&lt;P&gt;Hi Jaracan-&lt;BR /&gt;
We were on 6.63 in Enterprise and ES on 5.01.  We upgraded our ClusterMaster first (to 7.2.x), then upgraded our SHC and at the same time upgraded ES to 5.3.1.  After we confirmed 5.3.1 was happy, we upgraded our indexer cluster (to 7.2.x).  Everything went fine after our Searchhead cluster calmed down.  We had no issues with ES  or our indexer cluster. &lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;BR /&gt;
Mike &lt;/P&gt;</description>
    <pubDate>Wed, 08 Jan 2020 17:27:14 GMT</pubDate>
    <dc:creator>BainM</dc:creator>
    <dc:date>2020-01-08T17:27:14Z</dc:date>
    <item>
      <title>Splunk ES Upgrade Compatibility</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480412#M7684</link>
      <description>&lt;P&gt;Just a quick question on Splunk Upgrade for ES&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/CompatMatrix"&gt;https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/CompatMatrix&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;We are currently on Splunk ES v5.0.1 and Splunk Enterprise v7.0.13.1.&lt;/P&gt;

&lt;P&gt;Now,we wanted to version upgrade to Splunk ES v5.3.1 and Splunk Enterprise v7.2.9.1.&lt;/P&gt;

&lt;P&gt;With this, since we need to consider compatibility, do we need to upgrade to Splunk Enterprise v7.1.x first then upgrade Splunk ES App to v5.3.1, then we will upgrade to Splunk Enterprise v7.2.9.1 after? Is that correct? Or we can directly upgrade both from Splunk Enterprise v7.0.13.1 to v7.2.9.1 and Splunk ES App v5.0.1 to v5.3.1? Let me know which approach is correct. &lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 07:33:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480412#M7684</guid>
      <dc:creator>jaracan</dc:creator>
      <dc:date>2020-01-08T07:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Upgrade Compatibility</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480413#M7685</link>
      <description>&lt;P&gt;Hi Jaracan-&lt;BR /&gt;
We were on 6.63 in Enterprise and ES on 5.01.  We upgraded our ClusterMaster first (to 7.2.x), then upgraded our SHC and at the same time upgraded ES to 5.3.1.  After we confirmed 5.3.1 was happy, we upgraded our indexer cluster (to 7.2.x).  Everything went fine after our Searchhead cluster calmed down.  We had no issues with ES  or our indexer cluster. &lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;BR /&gt;
Mike &lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 17:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480413#M7685</guid>
      <dc:creator>BainM</dc:creator>
      <dc:date>2020-01-08T17:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Upgrade Compatibility</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480414#M7686</link>
      <description>&lt;P&gt;Forgot to note: Our ES is NOT clustered and runs as an independent searchhead, querying our indexer cluster. &lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 17:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480414#M7686</guid>
      <dc:creator>BainM</dc:creator>
      <dc:date>2020-01-08T17:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Upgrade Compatibility</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480415#M7687</link>
      <description>&lt;P&gt;I believe you can just upgrade directly from 7.0 to 7.2:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.9/Installation/AboutupgradingREADTHISFIRST"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.9/Installation/AboutupgradingREADTHISFIRST&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And then upgrade ES directly from 5.0 to 5.3: &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/ES/5.3.1/Install/Beforeupgrading"&gt;https://docs.splunk.com/Documentation/ES/5.3.1/Install/Beforeupgrading&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 17:31:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480415#M7687</guid>
      <dc:creator>lkutch_splunk</dc:creator>
      <dc:date>2020-01-08T17:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Upgrade Compatibility</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480416#M7688</link>
      <description>&lt;P&gt;Hi BainM, does this means you have directly upgrade the Splunk Enterprise from 6.63 to v7.2.x starting with the Cluster Master, then upgraded the Splunk Enterprise version of the ES Search Head from 6.63 to v7.2.x and the ES App version from v5.0.1 to v5.3.1, and then after its good, you had upgraded the  Splunk Enterprise version of the Peer Nodes/Clustered Indexers from 6.63 to v7.2.x. Is my understanding, correct?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 17:33:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480416#M7688</guid>
      <dc:creator>jaracan</dc:creator>
      <dc:date>2020-01-08T17:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Upgrade Compatibility</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480417#M7689</link>
      <description>&lt;P&gt;Correct.&lt;BR /&gt;&lt;BR /&gt;
We then upgraded the ES app after the main Splunk Ent. was at 7.2.x&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 17:56:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Upgrade-Compatibility/m-p/480417#M7689</guid>
      <dc:creator>BainM</dc:creator>
      <dc:date>2020-01-08T17:56:33Z</dc:date>
    </item>
  </channel>
</rss>

