Deployment Architecture

What is the recommended compatibility sequence of upgrading instances in my environment from Splunk 6.2.7 to 6.3.2?

rcreddy06
Path Finder

I have a deployment server, clustered Indexers, clustered search heads, heavy forwarders, & universal forwarders. All are running Splunk 6.2.7 and would like to upgrade to Splunk 6.3.2

I believe the compatibility sequence should be:
Cluster Master > Search Heads > Indexers > Heavy forwarders > Universal Forwarders and deployment server should be upgraded along with search heads or before cluster master.

I can't upgrade all servers on the same day. Please suggest compatibility of Splunk instances.

1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You can break down your upgrade in to phases.

First should be your Cluster Master Node.

Second, should be Search Tier. Upgrade the instances individually, or if you are on a SHC, you need to upgrade the whole cluster.

Next would be the indexing tier:

Put your CM in to Maintenance Mode, upgrade it, restart, put back into maintenance mode. Upgrade all your indexers, once upgraded, take the CM out of Maintenance mode. This is a good check point to make sure your Cluster(s) rebalance and are reporting in correctly.

Your DS / HF / UF can be upgraded as time permits, they dont have specific version requirements. (Although check the DS, if you're using some legacy configuration settings, they may be deprecated.)

Make note, there are some version requirements between the Search and Indexing tiers to be cautious about..

Upgrading : http://docs.splunk.com/Documentation/Splunk/6.3.2/Installation/HowtoupgradeSplunk
Upgrading Version Notes : http://docs.splunk.com/Documentation/Splunk/6.3.2/Installation/Aboutupgradingto6.3READTHISFIRST
Version Compatibility : http://docs.splunk.com/Documentation/Splunk/6.3.2/Indexer/Systemrequirements#Splunk_Enterprise_versi...

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

You can break down your upgrade in to phases.

First should be your Cluster Master Node.

Second, should be Search Tier. Upgrade the instances individually, or if you are on a SHC, you need to upgrade the whole cluster.

Next would be the indexing tier:

Put your CM in to Maintenance Mode, upgrade it, restart, put back into maintenance mode. Upgrade all your indexers, once upgraded, take the CM out of Maintenance mode. This is a good check point to make sure your Cluster(s) rebalance and are reporting in correctly.

Your DS / HF / UF can be upgraded as time permits, they dont have specific version requirements. (Although check the DS, if you're using some legacy configuration settings, they may be deprecated.)

Make note, there are some version requirements between the Search and Indexing tiers to be cautious about..

Upgrading : http://docs.splunk.com/Documentation/Splunk/6.3.2/Installation/HowtoupgradeSplunk
Upgrading Version Notes : http://docs.splunk.com/Documentation/Splunk/6.3.2/Installation/Aboutupgradingto6.3READTHISFIRST
Version Compatibility : http://docs.splunk.com/Documentation/Splunk/6.3.2/Indexer/Systemrequirements#Splunk_Enterprise_versi...

rcreddy06
Path Finder

From: http://docs.splunk.com/Documentation/Splunk/6.3.2/Indexer/Systemrequirements#Splunk_Enterprise_versi...
Cluster master should be upgraded before search heads, then indexers.

Lucas_K
Motivator

^ this!

Very bad things happen if you do search heads first.

We had a situation when another admins search head got a day one upgrade without us knowing.

We suddenly had indexers start going offline due to incompatibilities. It was the first time we had search head causing indexer outages.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Thanks for the call out, updated.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...