Deployment Architecture

Upgrade plan and path From 7.2 to 8.0

abhic25
Explorer

I have two queries Here - 

1. I am planning to upgrade my Environment to 8.0, I am not 100% sure about my upgrade plan, can anyone confirm if this would be the correct strategy?

2. Also, I am not sure on How upgrading Heavy Forwarder. Any steps will help here.

 

Role

Current Version

Intermediate update

Target Version

Search Head, Deployment, License Mgr.

7.2.6

NA

8.0

Indexer

7.2.6

NA

8.0

Heavy Forwarder

6.5.2

7.2

8.0

Heavy Forwarder

6.5.2

7.2

8.0

Universal Forwarders

6.5.2

7.2

8.0

 

  1. Upgrade Heavy Forwarder to 7.2
  2. Upgrade UF to 7.2
  3. Upgrade all Splunk Apps.

  4. Upgrade Search Head to 8.0

  5. Upgrade Indexer to 8.0 

  6. Upgrade Heavy Forwarders to 8.0
  7. Upgrade Heavy Forwarders to 8.0 
  8. Upgrade Universal Forwarders to 8.0
Tags (1)
0 Karma
1 Solution

aasabatini
Motivator

Hi @abhic25 

 

to upgrade the HF you need to stop and reinstall the new version.

don't worry the hf buffer the info for the time you install the new version and you don't lost any data.

Please check this link for the version.

https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

and if you use SSL connection check  che certficates expiration

https://docs.splunk.com/Documentation/Splunk/8.1.3/Security/AboutsecuringyourSplunkconfigurationwith...

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

View solution in original post

aasabatini
Motivator

Hi @abhic25 

 

your splunk enviroment have a cluster configuration?

Because the cluster configuration needs a defined list of steps

https://docs.splunk.com/Documentation/Splunk/8.1.3/Indexer/Upgradeacluster

If your splunk enviroment is not a cluster configuration your upgrade plan should be works.

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

abhic25
Explorer

@aasabatini thanks for reply, 

Its not distributed environment. 

1 SH

1 Indexer

2 HF

Also, need to understand. how to upgrade HF.

Tags (1)
0 Karma

aasabatini
Motivator

Hi @abhic25 

 

to upgrade the HF you need to stop and reinstall the new version.

don't worry the hf buffer the info for the time you install the new version and you don't lost any data.

Please check this link for the version.

https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

and if you use SSL connection check  che certficates expiration

https://docs.splunk.com/Documentation/Splunk/8.1.3/Security/AboutsecuringyourSplunkconfigurationwith...

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...