Getting Data In

Splunk license master upgradation

vikram_m
Path Finder

We have 3 Indexers, 2 Search Heads, 1 Master Indexer/License Master/Deployment server all instances working on 6.3.

We are planning to upgrade Splunk to 6.5, but for initial stage we are planning to go with an upgrade only for Master Indexer which is a license master as well for us and later rest of the servers can be upgraded.

Please suggest if any plan we can go ahead with to get the infra upgraded to 6.5 Splunk or the entire cluster needs to be upgraded at once.

Thanks.
Vikram,.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi vikram_m,
have you already seen these two documents?

all the needed steps are described.
Every way, if you upgrade a part of your Indexers cluster (Master Node) you have to upgrade all your cluster, so in your architecture remain only Seach Heads, but at this point upgrade all!
I suggest to test your apps before upgrading, eventually as first step on only one Search Head.
Bye.
Giuseppe

View solution in original post

0 Karma

vikram_m
Path Finder

Splunk's response.

As per the case description, I understand that all your splunk instances are running on 6.3.0 version and you want to upgrade your Cluster master/license master/Deployment server to 6.5 version.

I believe your indexers are in cluster mode and a single splunk instance is acting as "Cluster master/license master/Deployment server". Please correct me if I am wrong.

First you can upgrade your Cluster master/license master/Deployment server(from 6.3 to 6.5 version). The cluster master and cluster peers can be on different versions but the version of the cluster master should be higher than the cluster peers(indexers).

So in your environment all the splunk instances are on 6.3 version, if you upgrade the cluster master to 6.5 version, there will be no compatibility issue.

Please refer the below link:

http://docs.splunk.com/Documentation/Splunk/6.5.3/Indexer/Systemrequirements#Splunk_Enterprise_versi...

We recommend a dedicated splunk instance for cluster master. For better functioning and performance of cluster master, we suggest you to deploy an another splunk instance for deployment server and License master.

Note:
As a support team, we recommend you to get all your splunk instances to the same version.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi vikram_m,
have you already seen these two documents?

all the needed steps are described.
Every way, if you upgrade a part of your Indexers cluster (Master Node) you have to upgrade all your cluster, so in your architecture remain only Seach Heads, but at this point upgrade all!
I suggest to test your apps before upgrading, eventually as first step on only one Search Head.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...