Installation

How to upgrade from Splunk 4.2.2 to latest version and can I keep indexed data?

05500
New Member

Splunk current version is 4.2.2.
We want to upgrade to the latest version.

Question:
1. After version is up, can I keep old indexed data? it means old data is not lost?
2. Is there a detailed manual for upgrade on the Splunk site or etc?

Labels (1)
Tags (1)
0 Karma

MuS
Legend

Hi 05500,

Do backup's before upgrading! This will save you headaches.....
Next read the docs http://docs.splunk.com/Documentation/Splunk/6.2.1/Installation/HowtoupgradeSplunk#Upgrade_from_4.3_a... and if possible do a dry run on some dev/test server.

You should not loose any data because Splunk will not overwrite any existing indexes, but still remember to do backup's ....

Good luck ...

cheers, MuS

satishsdange
Builder

Hi -

Upgrading directly to version 6.2 from version 4.3 and earlier is not officially supported.

If you run version 4.3, upgrade to version 6.0 first before attempting an upgrade to 6.2.
If you run version 4.2, upgrade to version 5.0 first before attempting an upgrade to 6.2.
If you run a version earlier than 4.2, upgrade to version 4.3 first, then upgrade to version 6.0 before attempting an upgrade to 6.2. Read "About upgrading to 4.3 READ THIS FIRST" for specific details on how to upgrade to version 4.3. 

For more information , please refer to http://docs.splunk.com/Documentation/Splunk/6.2.1/Installation/HowtoupgradeSplunk

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...