Getting Data In

Does a cluster supports multiple version of splunk??

Anu
Path Finder

Hi all,

I have 3 search heads as a part of search head cluster and 5 indexers in the indexer cluster and also my search heads are also part of this indexer cluster. I'm upgrading my splunk infrastrcture from 6.63 to 7.2.Should all the search heads and indexers be upgraded at the same time or can i upgrade the search head cluster first and indexer cluster later?? The problem here is search heads are also part of indexer cluster if i upgrade the search heads will i run into problem with different versions of splunk in indexer cluster

searchhead cluster components

sh1

sh2

sh3

indexer cluster

idx1

idx2

idx3

idx4

idx5

sh1

sh2

sh3

 

@isoutamo 

Labels (3)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

In normal situation those should be at same level. But when you are updating those there could be a situation when some part of distributed environment could be at different level.

But as you are updating from 6.6.3 to 7.2.x (you should consider to update at least 7.3.x), I afraid that you must do that update as offline all nodes at same time. After you have later versions 7.x you could do online upgrade but not now. 

https://community.splunk.com/t5/Installation/What-s-the-order-of-operations-for-upgrading-Splunk-Ent...

You must read exact steps from https://docs.splunk.com/Documentation/Splunk/7.2.10/Installation/HowtoupgradeSplunk

Splunk Enterprise version 7.2 will no longer be supported as of April 30, 2021.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

In normal situation those should be at same level. But when you are updating those there could be a situation when some part of distributed environment could be at different level.

But as you are updating from 6.6.3 to 7.2.x (you should consider to update at least 7.3.x), I afraid that you must do that update as offline all nodes at same time. After you have later versions 7.x you could do online upgrade but not now. 

https://community.splunk.com/t5/Installation/What-s-the-order-of-operations-for-upgrading-Splunk-Ent...

You must read exact steps from https://docs.splunk.com/Documentation/Splunk/7.2.10/Installation/HowtoupgradeSplunk

Splunk Enterprise version 7.2 will no longer be supported as of April 30, 2021.

r. Ismo

0 Karma

Anu
Path Finder

So what you meant is i should upgrade the indexer cluster and search head cluster at the same time.Is it possible upgrade to 7.3.x directly from 6.6.3??

0 Karma

isoutamo
SplunkTrust
SplunkTrust

It's possible but it must do as offline update. all in one time

If I recall right this is how we done it on one of our Client environment.

r. Ismo

0 Karma

Anu
Path Finder

Thank you Ismo.Is it possible to upgrade from 6.6.3 to 7.3 directly??

0 Karma

isoutamo
SplunkTrust
SplunkTrust

I think that offline upgrade should work. Of course you should take backups first so if there will be any real issues, you could go back to the previous version.

r. Ismo

 

0 Karma

Anu
Path Finder

Thank you .Just a last question, How do i verify all the apps/add-ons are working fine after the upgrade??

0 Karma

isoutamo
SplunkTrust
SplunkTrust

I haven’t any general way to do it automatically. You must just check those manually if you haven’t any other way to do it. 

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...