Hi,
I'm planning our Splunk cluster upgrade.
I would like to have an estimate of the time of update platform from 5 to 6.
Specifically, do you know if the DB files (3 TB) will be updated too and then I'll have to wait the end oh this operation before the system back online?
Any experience on this?
Thank you.
First off, read and understand this: http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Upgradeacluster#Upgrade_from_5.x_to_6.x
There's no need to churn through the entire index during upgrade, so your storage size doesn't really matter. I assume your cluster is only a couple of machines and not hundreds and doesn't have anything weird or fancy hacked into it that needs to be pampered... a reasonably skilled Splunker should do the upgrade in a few hours, with likely less than an hour of actual downtime.
First off, read and understand this: http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Upgradeacluster#Upgrade_from_5.x_to_6.x
There's no need to churn through the entire index during upgrade, so your storage size doesn't really matter. I assume your cluster is only a couple of machines and not hundreds and doesn't have anything weird or fancy hacked into it that needs to be pampered... a reasonably skilled Splunker should do the upgrade in a few hours, with likely less than an hour of actual downtime.
My environment is very similar to that described by ofrachon... so I expect similar times.
Thank you very much 🙂
The link shared by Martin is essential to the upgrade. Read it at least twice 🙂
I did an upgrade of a 5.0.7 cluster about two weeks ago. The target was Splunk 6.1.1.
One Search Head, one Master Node, three Peers with about 7 TB each of data.
The upgrade itself took about 15 minutes.
The cluster synchronization afterwards took about 2 hours to get everything searchable and replicated !