We wish to upgrade from 8.1.3 to the latest (9.0.1 at this time).
From my reading of:
it looks like we can follow below path:
Manager Node 1
Manager Node 2
Indexer Cluster 1 (2 nodes)
indexer cluster 2 (2 nodes)
Please advise if this will work correctly?
in your situation, I'd upgrade:
Hi @gcusello ,
Thank you for your response. After reading the documentation ( https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/UpgradeyourdistributedSplunkEnterpri...) there was one point that caught my eye :
To upgrade an environment with index clusters, see Upgrade an indexer cluster in Managing Indexers and Clusters of Indexers
As we do have distributed environment with 2 separate index clusters and each connected to 1 Master Node but only one search head, Should I not be following the upgrade an indexer cluster steps and follow Master Node-> SH -> Index Clusters?
https://community.splunk.com/t5/Installation/What-s-the-order-of-operations-for-upgrading-Splunk-Ent... that instructions for update order is still valid when you are doing live update.
When you have nodes which have several roles just look which role needs to update first based on above instruction.
here you can find the correct upgrade path: https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/HowtoupgradeSplunk
As you can see, you can directly upgrade from 8.1.3 to 9.0.1.
About the sequence to follow, you can find all the information at https://docs.splunk.com/Documentation/Splunk/9.0.1/Installation/UpgradeyourdistributedSplunkEnterpri...
So your order isn't correct, you have to upgrade:
If you have two Indexers Clusters, completely upgrade one (master node and Indexers) and then the second.
At least Forwarders.
remember to check the version of your Forwarders to be sure that all of them are complatible with 9.0.1 at https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar....