Installation

Can you give me advice on the correct sequence to follow when upgrading Splunk Enterprise from 8.1.3 to 9.0.1?

supreet
Explorer

We wish to upgrade from 8.1.3 to the latest (9.0.1 at this time).

We have:

  • Search Head
  • Manager Node 1 
  • Index Cluster (2 nodes)
  • Heavy forwarder 1(1 node)
  • Manager Node 2
  • Index Cluster (2 nodes)
  • Heavy forwarder 2 (1 node)

From my reading of:

https://docs.splunk.com/Documentation/Splunk/9.0.1/Indexer/Upgradeacluster#Upgrade_each_tier_separat...

it looks like we can follow below path: 

HF1, HF2

Manager Node 1 

Manager Node 2 

Search Head

Indexer Cluster 1 (2 nodes)

indexer cluster 2 (2 nodes)

Please advise if this will work correctly? 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @supreet,

in your situation, I'd upgrade:

  • SH
  • MN1
  • IDXs Cluster 1
  • MN2
  • IDXs Cluster 2 
  • HFs

Ciao.

Giuseppe

View solution in original post

supreet
Explorer

Hi @gcusello ,

Thank you for your response. After reading the documentation ( https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/UpgradeyourdistributedSplunkEnterpri...) there was one point that caught my eye : 

To upgrade an environment with index clusters, see Upgrade an indexer cluster in Managing Indexers and Clusters of Indexers

As we do have distributed environment with 2 separate index clusters and each connected to 1 Master Node but only one search head, Should I not be following the upgrade an indexer cluster steps and follow Master Node-> SH -> Index Clusters?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @supreet,

in your situation, I'd upgrade:

  • SH
  • MN1
  • IDXs Cluster 1
  • MN2
  • IDXs Cluster 2 
  • HFs

Ciao.

Giuseppe

isoutamo
SplunkTrust
SplunkTrust

Hi

https://community.splunk.com/t5/Installation/What-s-the-order-of-operations-for-upgrading-Splunk-Ent... that instructions for update order is still valid when you are doing live update.

When you have nodes which have several roles just look which role needs to update first based on above instruction.

  1. SH/LM (I suppose that this is your LM, if not then update this after MNs have updated)
  2. Both MN
  3. If your LM is somewhere else than SH, then SH other
  4. One index at time on those cluster
  5. HFs 
  6. UFs

r. Ismo

gcusello
SplunkTrust
SplunkTrust

Hi @supreet,

here you can find the correct upgrade path: https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/HowtoupgradeSplunk

As you can see, you can directly upgrade from 8.1.3 to 9.0.1.

About the sequence to follow, you can find all the information at https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/UpgradeyourdistributedSplunkEnterpri...

So your order isn't correct, you have to upgrade:

  • Search Heads,
  • Master Node,
  • Indexers,
  • Heavy Forwarders,

If you have two Indexers Clusters, completely upgrade one (master node and Indexers) and then the second.

At least Forwarders.

  • Search Heads,
  • Master Node1,
  • Indexers Cluster 1,
  • Master Node2,
  • Indexers Cluster 2,
  • Heavy Forwarders,

remember to check the version of your Forwarders to be sure that all of them are complatible with 9.0.1 at https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...