Installation

How to upgrade the one indexer in indexer cluster

Mayanakhan
Explorer

Hi,

Recently we have upgraded the splunk indexer cluster to 7.2.6 but our team is miss to upgrade one indexer node. Can anyone help with the process of upgrading the single indexer node in a cluster from 7.0.4 to 7.2.6.

Labels (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Follow instruction of step 3 - Upgrade the peer node tier on that indexer node.

https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Upgradeacluster#Upgrade_each_tier_separat...

So basically,

  1. Run splunk enable maintenance-mode on the master. To confirm that the master is in maintenance mode, run splunk show maintenance-mode on the master. This step prevents unnecessary bucket fix-ups.
  2. Stop Splunk on the peer nodes. When bringing down the peer, use the splunk stop command, not splunk offline.
  3. Upgrade the peer nodes, following the normal procedure for any Splunk Enterprise upgrade.
  4. Start the peer nodes, if they are not already running.
  5. Run splunk disable maintenance-mode on the master.

View solution in original post

somesoni2
Revered Legend

Follow instruction of step 3 - Upgrade the peer node tier on that indexer node.

https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Upgradeacluster#Upgrade_each_tier_separat...

So basically,

  1. Run splunk enable maintenance-mode on the master. To confirm that the master is in maintenance mode, run splunk show maintenance-mode on the master. This step prevents unnecessary bucket fix-ups.
  2. Stop Splunk on the peer nodes. When bringing down the peer, use the splunk stop command, not splunk offline.
  3. Upgrade the peer nodes, following the normal procedure for any Splunk Enterprise upgrade.
  4. Start the peer nodes, if they are not already running.
  5. Run splunk disable maintenance-mode on the master.
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...