Deployment Architecture

Can monitoring console v9.x support search peers v8.1.5 ?

dm1
Contributor

Our monitoring console is also acting as a deployment server.

As per SVD-2022-0608 vulnerability, we need to upgrade our deployment server to v9.x, however, considering its sharing the role of monitoring console as well, I was wondering whether MC supports compability with peers v8.1.5 ?

From the docs, it states

The search head must be at the same or a higher level than the search peers. 

So it looks like it may be possible.

Can someone please advise if there would be any issues with this ?

Tags (2)
0 Karma
1 Solution

gcusello
Esteemed Legend

Hi @dm1,

in general, if your Deployment Server has to manage many clients it isn't a good idea to use it also for another role, even if the Monitor Console.

Anyway, as you said, the MC is a Search Head and it has to te have a release equal or greter than the Search peers.

There shouldn't be any problem, is this a your doubt before the upgrade or have you an issue?

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
Esteemed Legend

Hi @dm1,

in general, if your Deployment Server has to manage many clients it isn't a good idea to use it also for another role, even if the Monitor Console.

Anyway, as you said, the MC is a Search Head and it has to te have a release equal or greter than the Search peers.

There shouldn't be any problem, is this a your doubt before the upgrade or have you an issue?

Ciao.

Giuseppe

0 Karma

gcusello
Esteemed Legend

Hi @dm1,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

gcusello
Esteemed Legend

Hi @dm1,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

dm1
Contributor

Our Dep Server does'n't have more than 30 clients, so all good.

Yes, it was just my doubt.

0 Karma

gcusello
Esteemed Legend

Hi @dm1,

in this case there isn't any problem.

Only one final doubt: why do you want to upgrade only DS and not also Search peers?

it's always a best practice to have the same version in all components, the rule of greater version is usually only for special or temporary conditions, usually the version is the same.

Ciao.

Giuseppe

0 Karma

PickleRick
Ultra Champion

I can answer that 🙂

It's way easier to simply quickly upgrade one component due to a CVE than to plan the whole upgrade process of a distributed environment (especially that upgrading to x.0.0 versions is always risky and many admins tend to avoid it; and I can't blame them).

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...