Installation

Cluster upgrade 5.0.5 to 6.1.2 - Estimate on how long?

ctux
Path Finder

Hi,

I'm planning our Splunk cluster upgrade.
I would like to have an estimate of the time of update platform from 5 to 6.

Specifically, do you know if the DB files (3 TB) will be updated too and then I'll have to wait the end oh this operation before the system back online?

Any experience on this?

Thank you.

Tags (3)
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

First off, read and understand this: http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Upgradeacluster#Upgrade_from_5.x_to_6.x

There's no need to churn through the entire index during upgrade, so your storage size doesn't really matter. I assume your cluster is only a couple of machines and not hundreds and doesn't have anything weird or fancy hacked into it that needs to be pampered... a reasonably skilled Splunker should do the upgrade in a few hours, with likely less than an hour of actual downtime.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

First off, read and understand this: http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Upgradeacluster#Upgrade_from_5.x_to_6.x

There's no need to churn through the entire index during upgrade, so your storage size doesn't really matter. I assume your cluster is only a couple of machines and not hundreds and doesn't have anything weird or fancy hacked into it that needs to be pampered... a reasonably skilled Splunker should do the upgrade in a few hours, with likely less than an hour of actual downtime.

ctux
Path Finder

My environment is very similar to that described by ofrachon... so I expect similar times.

Thank you very much 🙂

0 Karma

ofrachon
Path Finder

The link shared by Martin is essential to the upgrade. Read it at least twice 🙂

I did an upgrade of a 5.0.7 cluster about two weeks ago. The target was Splunk 6.1.1.

One Search Head, one Master Node, three Peers with about 7 TB each of data.

The upgrade itself took about 15 minutes.

The cluster synchronization afterwards took about 2 hours to get everything searchable and replicated !

Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...