Getting Data In

While upgrading a setup of 2 non-pooled SH and 4 Indexer clusters to Splunk 6.6, when should I upgrade SH and Apps ?

abhinav_maxonic
Path Finder

I have to upgrade 2 SH and 4 indexer clusters from Splunk 6.3 to Splunk 6.6. SearchHeads are not pooled. I'll be upgrading indexer cluster sequentially, upgrading one indexer cluster at a time. I have 2 question

  1. Should I update SH after upgrading and starting all indexer clusters or before upgrading Indexer clusters ?
  2. When should I update my apps on SH and indexers ?

Because If I update 1 SH and 1 indexer cluster and their apps, then apps and add-ons might not work well on other indexer clusters and if I update all 4 indexers cluster and their apps first and then upgrade SH and its apps and add-ons then also apps might not work properly on both indexers and SHs till all apps and add-ons are upgraded on all indexers and SH.

0 Karma
1 Solution

adonio
Ultra Champion

hello there,
read here for two options:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster
option 1 upgrade all tiers at once:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_all_tiers_at_once
option 2 upgrade tiers seperately:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_each_tier_separate...
i recommend option 2
regarding the apps, upgrade those after you upgraded your environment
start with the search heads and then the indexers by pushing the new app version from cluster master
note: read upgrade instructions as some apps require slightly different process
note: always backup your splunk before upgrading and if not possible, make sure to run diag on all instances
hope it helps

View solution in original post

adonio
Ultra Champion

hello there,
read here for two options:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster
option 1 upgrade all tiers at once:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_all_tiers_at_once
option 2 upgrade tiers seperately:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Indexer/Upgradeacluster#Upgrade_each_tier_separate...
i recommend option 2
regarding the apps, upgrade those after you upgraded your environment
start with the search heads and then the indexers by pushing the new app version from cluster master
note: read upgrade instructions as some apps require slightly different process
note: always backup your splunk before upgrading and if not possible, make sure to run diag on all instances
hope it helps

abhinav_maxonic
Path Finder

Thanks! Any specific advantage in using option 2 over option 1 ?

0 Karma

adonio
Ultra Champion

i guess its a personal preference,
i like to have hands on process and also if something breaks, I know exactly where and when it was broken
which is helpful (for me) for a faster recovery.
cheers

0 Karma

abhinav_maxonic
Path Finder

Ok. So I have decided to follow below sequence for upgrading my Splunk environment:
1. Upgrade Cluster Master
2. Upgrade both SHs and their apps.
3. Upgrade Indexer and their apps via master.
I choose to upgrade apps before upgrading complete environment because lastest version of most of my apps are compatible with my current version of Splunk i.e Splunk 6.3 .

Now for rest of 3 clusters:
1. Upgrade Cluster master
2. Upgrade Indexer and their apps via master.

0 Karma

adonio
Ultra Champion

@abhinav_maxonic,
glad you have a process set.
if it answers your question, please mark it as answered.
cheers

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...