Getting Data In

Questions regarding Universal Forwarder upgrade prerequisites, backup, downtime, and CLI authentication

sri2splunk
Explorer

1) What are the prerequisites and requirements for upgrading Splunk Universal Forwarder?
2) We would appreciate it if you could provide the recommended backup and rollback procedures.

Labels (1)
1 Solution

sri2splunk
Explorer

Hello,

Please find the answers below.

1) Prerequisites and requirements for upgrading Splunk Universal Forwarder

Before upgrading the Splunk Universal Forwarder, it is recommended to verify the following:

  • Operating system compatibility: Verify that the operating system is supported by the target Universal Forwarder version.
  • Supported upgrade path: Review the supported upgrade path and any upgrade considerations for the target version.
  • App/Add-on compatibility: Verify the compatibility of any installed apps or add-ons with the target version by reviewing the respective Splunkbase pages.
  • Disk space: Ensure sufficient disk space is available for the upgrade.
  • Release notes: Review the release notes and known issues for the target version before proceeding.

Therefore, the understanding that the prerequisites primarily involve verifying operating system compatibility and installed app/add-on compatibility is correct. However, the supported upgrade path, available disk space, release notes, and any version-specific upgrade considerations should also be reviewed.

References:

About upgrading to 10.2 – READ THIS FIRST:
https://help.splunk.com/en/splunk-enterprise/administer/install-and-upgrade/10.2/upgrade-or-migrate-...

System requirements:
https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.2/plan-your-splunk-e...

Upgrade the Universal Forwarder:
https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/universal-forwarder-manual/10....

2) Recommended backup and rollback procedures

Before upgrading the Universal Forwarder, it is recommended to back up the existing installation configuration, particularly the $SPLUNK_HOME/etc directory. This directory contains important configuration files such as inputs.conf, outputs.conf, deploymentclient.conf, server.conf, and any custom apps or local configurations.

If the Universal Forwarder is managed by a Deployment Server, it is also recommended to ensure that the relevant deployment apps are backed up on the Deployment Server.

If rollback is required, the general approach is:

  1. Stop the Universal Forwarder service.
  2. Reinstall the previous Universal Forwarder version.
  3. Restore the backed-up configuration files, if necessary.
  4. Start the Universal Forwarder service.
  5. Verify that data forwarding resumes successfully.

Splunk normally preserves the existing configuration during an upgrade. However, maintaining a backup before the upgrade is recommended to support recovery if any issue occurs.

Reference:

Back up configuration information:
https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/administer-splunk-enterpri...

View solution in original post

sri2splunk
Explorer

Hello,

Please find the answers below.

1) Prerequisites and requirements for upgrading Splunk Universal Forwarder

Before upgrading the Splunk Universal Forwarder, it is recommended to verify the following:

  • Operating system compatibility: Verify that the operating system is supported by the target Universal Forwarder version.
  • Supported upgrade path: Review the supported upgrade path and any upgrade considerations for the target version.
  • App/Add-on compatibility: Verify the compatibility of any installed apps or add-ons with the target version by reviewing the respective Splunkbase pages.
  • Disk space: Ensure sufficient disk space is available for the upgrade.
  • Release notes: Review the release notes and known issues for the target version before proceeding.

Therefore, the understanding that the prerequisites primarily involve verifying operating system compatibility and installed app/add-on compatibility is correct. However, the supported upgrade path, available disk space, release notes, and any version-specific upgrade considerations should also be reviewed.

References:

About upgrading to 10.2 – READ THIS FIRST:
https://help.splunk.com/en/splunk-enterprise/administer/install-and-upgrade/10.2/upgrade-or-migrate-...

System requirements:
https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.2/plan-your-splunk-e...

Upgrade the Universal Forwarder:
https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/universal-forwarder-manual/10....

2) Recommended backup and rollback procedures

Before upgrading the Universal Forwarder, it is recommended to back up the existing installation configuration, particularly the $SPLUNK_HOME/etc directory. This directory contains important configuration files such as inputs.conf, outputs.conf, deploymentclient.conf, server.conf, and any custom apps or local configurations.

If the Universal Forwarder is managed by a Deployment Server, it is also recommended to ensure that the relevant deployment apps are backed up on the Deployment Server.

If rollback is required, the general approach is:

  1. Stop the Universal Forwarder service.
  2. Reinstall the previous Universal Forwarder version.
  3. Restore the backed-up configuration files, if necessary.
  4. Start the Universal Forwarder service.
  5. Verify that data forwarding resumes successfully.

Splunk normally preserves the existing configuration during an upgrade. However, maintaining a backup before the upgrade is recommended to support recovery if any issue occurs.

Reference:

Back up configuration information:
https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/administer-splunk-enterpri...

VatsalJagani
SplunkTrust
SplunkTrust

@sri2splunk - Thanks for sharing Tip on Splunk Community. I'm accepting your answer as Accepted Solution, so future community member can get benefited from this. In the future when you share a Tip with both question and its answer, you can mark your own answer as a Accepted Solution as well so other users will be benefited or it.

 

Thanks!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...