Getting Data In

What is procedure to upgrade universal and heavy forwarders?

vrmandadi
Builder

Hello ,

We have around 13 heavy forwarders.How does the upgrade thing work , should we log into each instance and do the upgrade or is there any way to upgrade through the deployment server.The same way we have 500 + universal forwarders , what is the way to upgrade every U.F.

Thanks IN ADVANCE

0 Karma
1 Solution

masonmorales
Influencer

Splunk does not have a native feature for performing automatic/distributed upgrades of the software. We use Ansible internally to upgrade Splunk, but some customers use Chef, Salt, or Puppet to do it. For Windows, some customers use SCCM.

View solution in original post

0 Karma

Vijeta
Influencer

@vrmandadi you should not use deployment server for performing Splunk upgrade. For the Heavy forwarders it will be just like any other Splunk Enterprise instance upgrade.
For Universal forwarders on Windows and Linux you can use deployment tool for Windows like SCCM or script for Linux.
This document will be helpful for you for upgrading UF remotely. Do check for pre-requisites and whether you really need an upgrade for UFs.

https://docs.splunk.com/Documentation/Forwarder/7.3.1/Forwarder/UpgradetheWindowsuniversalforwarder
https://docs.splunk.com/Documentation/Forwarder/7.3.1/Forwarder/Upgradethenixuniversalforwarder

0 Karma

masonmorales
Influencer

Splunk does not have a native feature for performing automatic/distributed upgrades of the software. We use Ansible internally to upgrade Splunk, but some customers use Chef, Salt, or Puppet to do it. For Windows, some customers use SCCM.

0 Karma

pdantuuri0411
Explorer

Writing a script should be the most easy way to upgrade the forwarders. Splunk doesn't have an option to upgrade the forwarders automatically.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...