Deployment Architecture
Highlighted

Using different Splunk Version for Search Head Cluster as for the Indexer Cluster

Path Finder

Hi ninjas
I wonder wheter if it is supported having different splunk versions of the indexer cluster and the search head cluster.

Lets say we have an existing multiside indexer cluster and search head cluster running ond version 6.3x and i want to add an additonal search head cluster to that indexer cluster - can i go with the actual version of splunk for the new shc or should i use the same version as the existing ones?

Any one made experiences in that case? I didtnt found anything useful in the docs hop someone can help me out here.

Thanks in advance

0 Karma
Highlighted

Re: Using different Splunk Version for Search Head Cluster as for the Indexer Cluster

Influencer

I can't say whether or not it is supported, but we have run search heads and indexers with different minor versions without any trouble.

That said, it is advisable to run them all on the same version

0 Karma
Highlighted

Re: Using different Splunk Version for Search Head Cluster as for the Indexer Cluster

Splunk Employee
Splunk Employee

Hi salem34,

It is recommened that you bring your Splunk components to the same major version, since this is the kind of configurations and use scenarios that have been fully tested before GA release. Besides, version 6.5 introduces improvements to both the indexer and search head tiers:
- Indexer cluster data rebalancing
- Indexer clustering improvements Search
- Head clustering (SHC) improvements

Hope this helps. Thanks!
Hunter

Highlighted

Re: Using different Splunk Version for Search Head Cluster as for the Indexer Cluster

Path Finder

Hi Hunter
Thanks for the response - yeah im aware of all the changes and improvements in 6.5 - the thing is though that upgrading the exisitng 6.3 environment will be done in the near future - but adding an additonal sh cluster will be done asap so im just wondering if we should already use the newest version of splunk for that new shc even the existing shc and idxc are running still an old version. That would also be a way to compare the two shc versions.
What gives me headache are any hiddne compatibility issues between 6.5 and 6.3 as there where a lot of changes (as you also mentioned) in 6.5 when it comes to clustering.

Cheers

0 Karma
Highlighted

Re: Using different Splunk Version for Search Head Cluster as for the Indexer Cluster

Splunk Employee
Splunk Employee

Compatibility requirements for nodes in an indexer cluster are listed here:

http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/Systemrequirements#Splunk_Enterprise_versi...

It contains a subsection that addresses search head and peer node compatibility:

http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/Systemrequirements#Compatibility_between_p...

It states: "Starting with 6.3, the peer nodes and search heads can run different versions from each other. The search heads must run the same or a later version from the peer nodes."

The end of that section also addresses the combined topology of indexer cluster and search head cluster: "Search head clusters participating in an indexer cluster have the same compatibility requirements as individual search heads."

If you fulfill the requirement that the search heads in each search head cluster run the same or a later version of Splunk from the peer nodes, there doesn't seem to be any additional requirement that the two search head clusters must be running the same version.

Within each search head cluster, however, all search heads must be running the same version. See:

http://docs.splunk.com/Documentation/Splunk/6.5.1/DistSearch/SHCsystemrequirements#Splunk_Enterprise...

View solution in original post

Highlighted

Re: Using different Splunk Version for Search Head Cluster as for the Indexer Cluster

Path Finder

Thanks Steve!

0 Karma