Installation

In what order do we upgrade our search head, indexer, deployment server, and heavy forwarder from Splunk 6.2.2. to 6.4?

brdr
Contributor

Hi,

We are upgrading all of our Splunk components from Splunk 6.2.2 to 6.4. Presently, we are NOT in a distributed environment. We have 4 (1 Search Head, 1 Indexer, 1 Deployment Server, 1 Heavy Forwarder) primary servers and a whole set of hosts with universal forwarders. The License Manager is installed on the SH.

What is recommended pecking order to upgrade the 4 servers above?

Thx

Labels (4)
0 Karma
1 Solution

javiergn
Super Champion

First thing you need to do is to read the following two docs:

http://docs.splunk.com/Documentation/Splunk/latest/Installation/Aboutupgradingto6.4READTHISFIRST
http://docs.splunk.com/Documentation/Splunk/6.4.0/ReleaseNotes/KnownIssues#Upgrade_issues

In terms of steps:
1. Test your apps and make sure they are compatible with 6.4
2. Upgrade Deployment Server (disable it first, then upgrade, do not restart it yet)
3. Upgrade Search Heads
4. Upgrade Indexers (once completed you can now restart your deployment server)
5. Upgrade Forwarders

More info here:
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...

View solution in original post

javiergn
Super Champion

First thing you need to do is to read the following two docs:

http://docs.splunk.com/Documentation/Splunk/latest/Installation/Aboutupgradingto6.4READTHISFIRST
http://docs.splunk.com/Documentation/Splunk/6.4.0/ReleaseNotes/KnownIssues#Upgrade_issues

In terms of steps:
1. Test your apps and make sure they are compatible with 6.4
2. Upgrade Deployment Server (disable it first, then upgrade, do not restart it yet)
3. Upgrade Search Heads
4. Upgrade Indexers (once completed you can now restart your deployment server)
5. Upgrade Forwarders

More info here:
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...

jmulcaster_splu
Splunk Employee
Splunk Employee

FYI, we've posted an upgrade roadmap with links to relevant documentation to help with upgrade planning. Check it out and let us know if you find it helpful. What's the order of operations for upgrading Splunk Enterprise?

0 Karma

brdr
Contributor

Awesome. Thanks for answer!

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...