Getting Data In

While upgrading a setup of 2 non-pooled SH and 4 Indexer clusters to Splunk 6.6, when should I upgrade SH and Apps ?

abhinav_maxonic
Path Finder

I have to upgrade 2 SH and 4 indexer clusters from Splunk 6.3 to Splunk 6.6. SearchHeads are not pooled. I'll be upgrading indexer cluster sequentially, upgrading one indexer cluster at a time. I have 2 question

  1. Should I update SH after upgrading and starting all indexer clusters or before upgrading Indexer clusters ?
  2. When should I update my apps on SH and indexers ?

Because If I update 1 SH and 1 indexer cluster and their apps, then apps and add-ons might not work well on other indexer clusters and if I update all 4 indexers cluster and their apps first and then upgrade SH and its apps and add-ons then also apps might not work properly on both indexers and SHs till all apps and add-ons are upgraded on all indexers and SH.

0 Karma
1 Solution

adonio
Ultra Champion

hello there,
read here for two options:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster
option 1 upgrade all tiers at once:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_all_tiers_at_once
option 2 upgrade tiers seperately:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_each_tier_separate...
i recommend option 2
regarding the apps, upgrade those after you upgraded your environment
start with the search heads and then the indexers by pushing the new app version from cluster master
note: read upgrade instructions as some apps require slightly different process
note: always backup your splunk before upgrading and if not possible, make sure to run diag on all instances
hope it helps

View solution in original post

adonio
Ultra Champion

hello there,
read here for two options:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster
option 1 upgrade all tiers at once:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_all_tiers_at_once
option 2 upgrade tiers seperately:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_each_tier_separate...
i recommend option 2
regarding the apps, upgrade those after you upgraded your environment
start with the search heads and then the indexers by pushing the new app version from cluster master
note: read upgrade instructions as some apps require slightly different process
note: always backup your splunk before upgrading and if not possible, make sure to run diag on all instances
hope it helps

abhinav_maxonic
Path Finder

Thanks! Any specific advantage in using option 2 over option 1 ?

0 Karma

adonio
Ultra Champion

i guess its a personal preference,
i like to have hands on process and also if something breaks, I know exactly where and when it was broken
which is helpful (for me) for a faster recovery.
cheers

0 Karma

abhinav_maxonic
Path Finder

Ok. So I have decided to follow below sequence for upgrading my Splunk environment:
1. Upgrade Cluster Master
2. Upgrade both SHs and their apps.
3. Upgrade Indexer and their apps via master.
I choose to upgrade apps before upgrading complete environment because lastest version of most of my apps are compatible with my current version of Splunk i.e Splunk 6.3 .

Now for rest of 3 clusters:
1. Upgrade Cluster master
2. Upgrade Indexer and their apps via master.

0 Karma

adonio
Ultra Champion

@abhinav_maxonic,
glad you have a process set.
if it answers your question, please mark it as answered.
cheers

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...