Getting Data In

Splunk universal forwarder upgrade

Praz_123
Communicator

I need to upgrade splunk uf in my windows VM from 8.2 version to 9.3.11 can anyone help me with the steps how will I do as I need all steps in brief and if possible please share screenshot.  Also please share the backup how will I take for 8.2 splunk universal fowarder

Also I had downloaded version of 9.3.11 splunk uf  .exe file

 

 

 

  •  
Labels (1)
0 Karma

Praz_123
Communicator

@gcusello @richgalloway  I already flow those steps to have an upgrade but am getting issue like .

While am running the line -  

Start-Process msiexec.exe -ArgumentList "/i `"$msiFile`" AGREETOLICENSE=Yes" -Wait

So it is asking me with the old version of the splunk UF and in the splunk release also on my computer I could not get the 8.2 version of the splunk UF but the path what it is ahowing the person had left the organization so how can i get that package .

Praz_123_0-1786606823102.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Praz_123 ,

the @richgalloway 's answer should answer to your question.

In addition I could say also that, if you need to upgrade many clients and you have a Deployment Server, you could use the "TA - Splunk UF Upgrade Automation for Windows" ( https://splunkbase.splunk.com/app/8802 ), but only from the next upgrade because it runs from the 9.0 version.

Ciao.

Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk has a manual describing how to upgrade the Windows Universal Forwarder (UF).  See https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/universal-forwarder-manual/9.4...

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...