Getting Data In

While upgrading a setup of 2 non-pooled SH and 4 Indexer clusters to Splunk 6.6, when should I upgrade SH and Apps ?

abhinav_maxonic
Path Finder

I have to upgrade 2 SH and 4 indexer clusters from Splunk 6.3 to Splunk 6.6. SearchHeads are not pooled. I'll be upgrading indexer cluster sequentially, upgrading one indexer cluster at a time. I have 2 question

  1. Should I update SH after upgrading and starting all indexer clusters or before upgrading Indexer clusters ?
  2. When should I update my apps on SH and indexers ?

Because If I update 1 SH and 1 indexer cluster and their apps, then apps and add-ons might not work well on other indexer clusters and if I update all 4 indexers cluster and their apps first and then upgrade SH and its apps and add-ons then also apps might not work properly on both indexers and SHs till all apps and add-ons are upgraded on all indexers and SH.

0 Karma
1 Solution

adonio
Ultra Champion

hello there,
read here for two options:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster
option 1 upgrade all tiers at once:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_all_tiers_at_once
option 2 upgrade tiers seperately:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_each_tier_separate...
i recommend option 2
regarding the apps, upgrade those after you upgraded your environment
start with the search heads and then the indexers by pushing the new app version from cluster master
note: read upgrade instructions as some apps require slightly different process
note: always backup your splunk before upgrading and if not possible, make sure to run diag on all instances
hope it helps

View solution in original post

adonio
Ultra Champion

hello there,
read here for two options:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster
option 1 upgrade all tiers at once:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_all_tiers_at_once
option 2 upgrade tiers seperately:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_each_tier_separate...
i recommend option 2
regarding the apps, upgrade those after you upgraded your environment
start with the search heads and then the indexers by pushing the new app version from cluster master
note: read upgrade instructions as some apps require slightly different process
note: always backup your splunk before upgrading and if not possible, make sure to run diag on all instances
hope it helps

abhinav_maxonic
Path Finder

Thanks! Any specific advantage in using option 2 over option 1 ?

0 Karma

adonio
Ultra Champion

i guess its a personal preference,
i like to have hands on process and also if something breaks, I know exactly where and when it was broken
which is helpful (for me) for a faster recovery.
cheers

0 Karma

abhinav_maxonic
Path Finder

Ok. So I have decided to follow below sequence for upgrading my Splunk environment:
1. Upgrade Cluster Master
2. Upgrade both SHs and their apps.
3. Upgrade Indexer and their apps via master.
I choose to upgrade apps before upgrading complete environment because lastest version of most of my apps are compatible with my current version of Splunk i.e Splunk 6.3 .

Now for rest of 3 clusters:
1. Upgrade Cluster master
2. Upgrade Indexer and their apps via master.

0 Karma

adonio
Ultra Champion

@abhinav_maxonic,
glad you have a process set.
if it answers your question, please mark it as answered.
cheers

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...