All Apps and Add-ons

We are currently running Splunk 5.0.4. What are the recommended actions to upgrade Splunk?

New Member


I'm currently running Splunk version 5.0.4 across 2 servers. One server is acting as the indexer & search head. The other is the heavy forwarder & deployment server. These are running on Windows 2008 R2 platform.
It has been deemed necessary to upgrade the Splunk version.

What is the recommended version to upgrade to from 5.0.4?
Will this version install over the existing version of Splunk installed without effecting any data or reports etc that have been created?
Will any of the universal forwarders require an upgrade also?
We have the S.o.S - Splunk on Splunk app installed currently, would this be affected?

Any help would be greatly appreciated.


0 Karma

Splunk Employee
Splunk Employee

Hi corners,

Upgrading from 5.0.4 to the latest release is supported, but you need to follow this upgrade path:

Upgrade from 5.0.4 to 6.3 first, and then from 6.3 to 6.5.

Of course, always backup before upgrading and always read the important upgrade information and changes first.

And you had better upgrade universal forwarders to the same version as your indexer and heavy forwarder.
Hope it helps. Thanks!
Hunter Shen

Splunk Employee
Splunk Employee

Hi corners,

Just to add to hunters' great answer and to address your question about S.o.S. - Splunk on Splunk:

According the S.o.S Splunkbase page, as of Splunk Enterprise 6.3, this app is End of Life. It has been replaced and superseded by the Distributed Management Console (DMC). But now as of 6.5.0, the DMC is now known as the Monitoring Console.

0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...