Deployment Architecture

Splunk Upgrade using tar method

sanjubaba
Path Finder

How to upgrade Splunk enterprise version using tar method?

Can someone guide me through the steps or documentation?

Labels (2)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

Most of the time, I don't backup data unless customer insist to take backup and provides storage. but it's recommended to take backup of  $SPLUNK_HOME/etc in case you would like to revert to old version for any reason. In that case backup is required as there is no roll-back option in Splunk. 

————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust

Most of the time, I don't backup data unless customer insist to take backup and provides storage. but it's recommended to take backup of  $SPLUNK_HOME/etc in case you would like to revert to old version for any reason. In that case backup is required as there is no roll-back option in Splunk. 

————————————
If this helps, give a like below.

sanjubaba
Path Finder

@thambisetty How to rollback changes if we face any issue during Splunk version upgradation?

Can you share me the documentation for it?

 

0 Karma

sanjubaba
Path Finder

@richgalloway Do we need to backup Splunk bucket folder before we proceed with Splunk version upgrade? Or we can directly upgrade without taking backup of bucket folder?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

richgalloway
SplunkTrust
SplunkTrust
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...