Installation

In what order do we upgrade our search head, indexer, deployment server, and heavy forwarder from Splunk 6.2.2. to 6.4?

brdr
Contributor

Hi,

We are upgrading all of our Splunk components from Splunk 6.2.2 to 6.4. Presently, we are NOT in a distributed environment. We have 4 (1 Search Head, 1 Indexer, 1 Deployment Server, 1 Heavy Forwarder) primary servers and a whole set of hosts with universal forwarders. The License Manager is installed on the SH.

What is recommended pecking order to upgrade the 4 servers above?

Thx

Labels (4)
0 Karma
1 Solution

javiergn
Super Champion

First thing you need to do is to read the following two docs:

http://docs.splunk.com/Documentation/Splunk/latest/Installation/Aboutupgradingto6.4READTHISFIRST
http://docs.splunk.com/Documentation/Splunk/6.4.0/ReleaseNotes/KnownIssues#Upgrade_issues

In terms of steps:
1. Test your apps and make sure they are compatible with 6.4
2. Upgrade Deployment Server (disable it first, then upgrade, do not restart it yet)
3. Upgrade Search Heads
4. Upgrade Indexers (once completed you can now restart your deployment server)
5. Upgrade Forwarders

More info here:
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...

View solution in original post

javiergn
Super Champion

First thing you need to do is to read the following two docs:

http://docs.splunk.com/Documentation/Splunk/latest/Installation/Aboutupgradingto6.4READTHISFIRST
http://docs.splunk.com/Documentation/Splunk/6.4.0/ReleaseNotes/KnownIssues#Upgrade_issues

In terms of steps:
1. Test your apps and make sure they are compatible with 6.4
2. Upgrade Deployment Server (disable it first, then upgrade, do not restart it yet)
3. Upgrade Search Heads
4. Upgrade Indexers (once completed you can now restart your deployment server)
5. Upgrade Forwarders

More info here:
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...

jmulcaster_splu
Splunk Employee
Splunk Employee

FYI, we've posted an upgrade roadmap with links to relevant documentation to help with upgrade planning. Check it out and let us know if you find it helpful. What's the order of operations for upgrading Splunk Enterprise?

0 Karma

brdr
Contributor

Awesome. Thanks for answer!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...