Deployment Architecture

How to upgrade a Splunk search head and indexer cluster from 6.3.2 to 6.5.1?

kml_uvce
Builder

Hi

We are doing upgrade from 6.3.2 to 6.5.1. We have a search head cluster and indexer cluster in our Splunk setup.

In doc http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/Upgradeacluster

First It says
"When you upgrade a 6.x indexer cluster, such as 6.2, to a later 6.x cluster, such as 6.3 or 6.4, you must take all cluster nodes offline. You cannot perform a rolling, online upgrade."

And later it says
"Perform the following steps:
1. Stop the master.
2. Stop all the peers and search heads.
When bringing down the peers, use the splunk stop command, not splunk offline."

So first it says you need to take all cluster nodes (Peer nodes) offline, and then second it says do not splunk offline command. It is confusing, so please help me. Should I use the splunk offline command or splunk stop command for peer nodes and search head nodes in a search head cluster?

kamal singh bisht
0 Karma
1 Solution

Steve_G_
Splunk Employee
Splunk Employee

The docs are regrettably inconsistent in their use of the term "offline". The phrase, "... you must take all cluster nodes offline" means that you must take down the nodes. As the later note states, you must perform that action via the splunk stop command.

I will fix the docs. Sorry for the confusion.

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

The docs are regrettably inconsistent in their use of the term "offline". The phrase, "... you must take all cluster nodes offline" means that you must take down the nodes. As the later note states, you must perform that action via the splunk stop command.

I will fix the docs. Sorry for the confusion.

Steve_G_
Splunk Employee
Splunk Employee

The docs have been updated to read, "When you upgrade a 6.x indexer cluster, such as 6.2, to a later 6.x cluster, such as 6.3 or 6.4, you must take down all cluster nodes. "

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...