Deployment Architecture

OS upgrade

btshivanand
Path Finder

We are planning to upgrade  splunk OS RHEL 6 to OL 7.its single site cluster environment.i have few of doubts.

What would be up-gradtion sequence?

do we need to consider upgrade all vms in one mantainance window?

is it ok if we upgrade indexers first and leave it for a week to see the performance and then we upgrade the search heads?is that ok to run with two different os in the splunk cluster.

Any help would be appreciated.

Regards,Shivanand

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Are you doing on line of off line update?

I would follow this order even you are not updating Splunk. https://community.splunk.com/t5/Installation/What-s-the-order-of-operations-for-upgrading-Splunk-Ent...

And as you are going to OL7 then I definitely test Splunk's configuration changes needed for it before production updates. If you cannot do that, then reserve enough time to check those within update and make plans how to do rollback if it's needed.

Main thing is that your Splunk version is same on both layer. Then it shouldn't be so big issue if OS is different for short time, but don't keep it different any longer than is mandatory. 

r. Ismo

0 Karma

btshivanand
Path Finder

Thanks for your reply .. We are doing offline update. 

Which are the splunk configurations need to check for this upgrade?

Regards,Shivanand

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Offline is much safer to do especially with full backups/snapshots.
It's hard to say what those could be, but you should prepare that there could be something or nothing if you are lucky ,-)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...