I have indexers, search heads, and forwarders that I want to upgrade to 4.2. Is there a suggested order in doing such things? I was thinking:
2) search heads
Is this logical?
Your order sounds good to me.
View solution in original post
@jmulcaster_splunk posted an order-of-operations diagram with links to relevant documentation to help with upgrade planning. Check it out and let us know if you find it helpful. What's the order of operations for upgrading Splunk Enterprise?