Deployment Architecture

Automated rolling upgrade of a search head cluster

FRTS777
New Member

I'm planning to upgrade a multi-site IDX & SHC environment to version 9.3 and i have question regarding the automated rolling upgrade feature 

https://docs.splunk.com/Documentation/Splunk/9.3.0/DistSearch/AutomatedSHCrollingupgrade

With the "Automated rolling upgrade of a search head cluster" feature there is the option to execute this on:

  • For cluster upgrade, you can run these operations on any cluster member.
  • For deployer upgrade, you must run these operation on the deployer.
  • For non-clustered upgrade, which means upgrading search heads that are not a part of a search head cluster, you must run these operations on each single search head.

Is it also possible to use this feature to upgrade CM, LM, MC, DS & HFW as part of non-clustered upgrade?

There is an option to execute on Deployer and License Manager,  so i assume i can also use it on the other (stand-alone) management nodes.

Any help would be much appreciated

 

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

This documentation is confusing. First it says about automating the rolling upgrade of SHC, then it lists upgrading standalone SH as a use case.

To be honest, I'd avoid using this app. If not for any other reason, it supports only using tgz archive to replace the running splunk instance whereas I tend to use system packages (rpm or deb) whenever possible.

0 Karma

FRTS777
New Member

From 9.3 you can also perform automated indexer cluster upgrade. Als in this doc there is a reference to upgrade LM & CM with the app, but they don't mention any other stand-alone servers.

https://docs.splunk.com/Documentation/Splunk/9.3.0/Indexer/AutomatedIDXCrollingupgrade#Run_the_autom...

Documentation is confusing 😞 

0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...