Deployment Architecture

In a distributed and clustered environ, which kvstores need migration to wiredTiger prior to upgrading to 9.0.4?

Glasses2
Communicator

I am about to upgrade 8.1.3 distributed / clustered environment to 9.0.4.

Per Docs> 

  • Migrate your App Key Value Store storage engine from the Memory Mapped (MMAP) storage engine to the Wired Tiger storage engine, and update your MongoDB version from 3.6 to 4.2. These updates are required in Splunk Enterprise 9.0. See Migrate the KV store storage engine in the Admin manual to plan your migration.
  • Back up your App Key Value Store (KV Store) databases prior to starting an upgrade. If you run version 7.1 and lower of Splunk Enterprise, you must stop Splunk Enterprise instances first.

I am going to do this part prior to the Upgrade.

I inherited this deployment so IDK where all the KVstore(s) are located or which nodes have a default KVstore needing the same migration/upgrade (e.g. MC or DS).

My Environment> SHC(4), SHC-deployer, IDXCM, IDXC(10), MC/LM, DS, HFs, UFs

Any advice appreciated.  If someone can share knowledge such as, how to validate KVstore locations and which KVstore(s) need update...  that would help.

 

Thank you

Thank you

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Indexers and UFs never use KVStore so no upgrades are needed there.

Definitely upgrade the SHs.

I'm on the fence regarding SHCD, CM, MC/LM, and DS.  Absent advice to the contrary, I'd play it safe and upgrade them.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

Glasses2
Communicator

I think, better safe than sorry, looks like some apps use KVstores... 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Indexers and UFs never use KVStore so no upgrades are needed there.

Definitely upgrade the SHs.

I'm on the fence regarding SHCD, CM, MC/LM, and DS.  Absent advice to the contrary, I'd play it safe and upgrade them.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...