Deployment Architecture

OS upgrade

btshivanand
Path Finder

We are planning to upgrade  splunk OS RHEL 6 to OL 7.its single site cluster environment.i have few of doubts.

What would be up-gradtion sequence?

do we need to consider upgrade all vms in one mantainance window?

is it ok if we upgrade indexers first and leave it for a week to see the performance and then we upgrade the search heads?is that ok to run with two different os in the splunk cluster.

Any help would be appreciated.

Regards,Shivanand

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Are you doing on line of off line update?

I would follow this order even you are not updating Splunk. https://community.splunk.com/t5/Installation/What-s-the-order-of-operations-for-upgrading-Splunk-Ent...

And as you are going to OL7 then I definitely test Splunk's configuration changes needed for it before production updates. If you cannot do that, then reserve enough time to check those within update and make plans how to do rollback if it's needed.

Main thing is that your Splunk version is same on both layer. Then it shouldn't be so big issue if OS is different for short time, but don't keep it different any longer than is mandatory. 

r. Ismo

0 Karma

btshivanand
Path Finder

Thanks for your reply .. We are doing offline update. 

Which are the splunk configurations need to check for this upgrade?

Regards,Shivanand

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Offline is much safer to do especially with full backups/snapshots.
It's hard to say what those could be, but you should prepare that there could be something or nothing if you are lucky ,-)
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...