Splunk recommends that before you upgrade a distributed environment, confirm that Splunk apps work on the version of Splunk Enterprise that you want to upgrade to.
But my query is what could go wrong if some Apps are missed and upgradation happened and that App are not compatible with 8.X.
Is there any chance that we can upgrade apps or add-on after upgraded to desired version or what are the options after upgrade.
Any one faced any similar situation like this?
Thank you in advance
Yes, you can upgrade apps after upgrading Splunk. Apps that do not use Python should be safe to run.
OTOH, I've seen Splunk 8 fail to start because an app was not upgraded to an 8-compatible version, so I strongly encourage you to upgrade all apps before upgrading Splunk.
Hi @richgalloway ,
Thank you so much for response really helpful for me.
One more help needed could you please elaborate below point no.3 which I found from How to upgrade a distributed Splunk Enterprise environment - Splunk Documentation in Upgrade the search heads section
Thanks
What is it you need elaborated? If you tested the app on a sandbox instance of Splunk (as per the doc) then this instruction is saying to copy the $SPLUNK_HOME/etc/apps/foo directory from the test instance to the SH.
I think I will test upgrade first on standalone instance and I will get my answers.
Thanks
Yes, you can upgrade apps after upgrading Splunk. Apps that do not use Python should be safe to run.
OTOH, I've seen Splunk 8 fail to start because an app was not upgraded to an 8-compatible version, so I strongly encourage you to upgrade all apps before upgrading Splunk.