Crossing your fingers might be a good precaution.
On a more serious note: without any further details, this is impossible to comment on. What OS, what is involved in the patching (e.g. are they going to reboot, or trigger splunk to restart), what does your splunk architecture look like, what availability requirements do you have...etc. etc.?