Deployment Architecture

How to upgrade Search head pooling in upgrading Splunk from 6.0.1 to 7.2.3

ramprakash
Explorer

Hi,

I need urgent assistance on upgrading Search head pooling. Mine is distributed environment(6.0.1) with below details

Two indexers(Clustered)
Two search heads(SHP)
One Cluster master

As per the Splunk docuemntation I need to upgrade in below sequence
Licence Master ->Search head ->Cluster master ->Indexer

For Search head pooling i have below doubt as mentioned in Splunk documents

Test apps prior to the upgrade
Before you upgrade a distributed environment, confirm that Splunk apps work on the version of Splunk Enterprise that you want to upgrade to. You must test apps if you want to upgrade a distributed environment with a search head pool, because search head pools use shared storage space for apps and configurations.
When you upgrade, the migration utility warns of apps that need to be copied to shared storage for pooled search heads when you upgrade them. It does not copy them for you. *
You must manually copy updated apps, including apps that ship with Splunk Enterprise (such as the Search app) - to shared storage during the upgrade process*. Failure to do so can cause problems with the user interface after you complete the upgrade.
On a reference machine, install the full version of Splunk Enterprise that you currently run.
Install the apps on this instance.
Access the apps to confirm that they work as you expect.
Upgrade the instance.
Access the apps again to confirm that they still work.
If the apps work as you expect, move them to the appropriate location during the upgrade of your distributed environment:
If you use non-pooled search heads, move the apps to $SPLUNK_HOME/etc/apps on each search head during the search head upgrade process.
If you use pooled search heads, move the apps to the shared storage location where the pooled search heads expect to find the apps.

My Question is

1) I have already apps placed on NAS. How can i copy and paste from Search head again ? Is this makes sense ?

PS:- I know Search head pooling is depreciated feature. We will upgrade to Search head clustering later as a different project.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi ramprakash,
as you said Search Head Pooling is a deprecated feature, but I didn't find any information about the version of removal.
Anyway, I think that you don't need to copy apps again because you already have them on NAS.
I had a very bad experience with Search Head Pooling upgrade, so if you don't need to upgrade now, maybe it could be better to wait and upgrade when you'll pass to Search Head Cluster.

Bye.
Giuseppe

View solution in original post

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...