I just take over a cluster (which is not in full productive mode yet) and i want to update all settings / apps before go live.
The Palo Alto App for example is on 4.x, available already is 5.x.
The cluster consists of Heavy Forwarders, Indexer Cluster and Search Heads (incl. Cluster Master and Management Server).
I can not find any documentation which tells me how to upgrade apps on such an setup.
So how to start, and in which order?
1. Create a new deplyoment app (deplyoment server) for the HF
2. Create a new shccluster app for the Search Heads
3. Create a new master app for the indexer cluster?
But what about the already installed Palo Alto App 4.x and the configuration files (local/transforms.conf...).
Do I need to uninstall the App first? Migrate the conf files by hand? Or is Splunk aware of the ugprade?