Installation

Main steps for upgradation of splunk

Mukunda7
Explorer

Hi,

We are trying to upgrade Splunk enterprise from 7.3.1 to 8.1.5 . What will be the first activity like

1. Which major files we need to take backup?

2.We need to upgrade the less impacted item first?

3. Search head,  monitoring console, indexers, deployment server what need to be updated first

4. Can we stop all indexers at a time during upgradation that cause any impact?

5. How about the forwarders upgradation?

Labels (2)
0 Karma
1 Solution

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Mukunda7 

1. Which major files we need to take backup?
I would suggest to take backup of splunk etc dirctory 

https://docs.splunk.com/Documentation/Splunk/8.2.2/Installation/HowtoupgradeSplunk#Phase_1:_Identify...


2.We need to upgrade the less impacted item first?
No, we need to upgarde the compnenets as per hirearchy 

3. Search head,  monitoring console, indexers, deployment server what need to be updated first
     

please upgrade in following order(which I folllowed when we upraded the infra)
                   
1.Clustmaster 
2.License Master
3.Search Head
4.Indexers (enable cluster master in maintenance )

5. Deployment server

6. forwarders

4. Can we stop all indexers at a time during upgradation that cause any impact??
     In point of View no need to stop all the indexers same time, you can stop indexers one by one 
enable clustermaster in maintenance mode  
  stop the indexer1 first and upgarde it and start the indexer 

for deatrlied steps for indexer upgrade please refer to
https://docs.splunk.com/Documentation/Splunk/8.0.1/Indexer/Upgradeacluster#Site-by-site_upgrade_for_...

5. How about the forwarders upgradation?
please upgrade the forwader at last once all higer componets are upgraded. please upgrade the forwaders few at a time, that hleps to continuous data to sent to splunk by other forwarders 

 

also please go throuth the following docs for upgrade related info

https://docs.splunk.com/Documentation/Splunk/8.2.2/Installation/AboutupgradingREADTHISFIRST

https://docs.splunk.com/Documentation/Splunk/8.2.2/Installation/HowtoupgradeSplunk

View solution in original post

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Mukunda7 

1. Which major files we need to take backup?
I would suggest to take backup of splunk etc dirctory 

https://docs.splunk.com/Documentation/Splunk/8.2.2/Installation/HowtoupgradeSplunk#Phase_1:_Identify...


2.We need to upgrade the less impacted item first?
No, we need to upgarde the compnenets as per hirearchy 

3. Search head,  monitoring console, indexers, deployment server what need to be updated first
     

please upgrade in following order(which I folllowed when we upraded the infra)
                   
1.Clustmaster 
2.License Master
3.Search Head
4.Indexers (enable cluster master in maintenance )

5. Deployment server

6. forwarders

4. Can we stop all indexers at a time during upgradation that cause any impact??
     In point of View no need to stop all the indexers same time, you can stop indexers one by one 
enable clustermaster in maintenance mode  
  stop the indexer1 first and upgarde it and start the indexer 

for deatrlied steps for indexer upgrade please refer to
https://docs.splunk.com/Documentation/Splunk/8.0.1/Indexer/Upgradeacluster#Site-by-site_upgrade_for_...

5. How about the forwarders upgradation?
please upgrade the forwader at last once all higer componets are upgraded. please upgrade the forwaders few at a time, that hleps to continuous data to sent to splunk by other forwarders 

 

also please go throuth the following docs for upgrade related info

https://docs.splunk.com/Documentation/Splunk/8.2.2/Installation/AboutupgradingREADTHISFIRST

https://docs.splunk.com/Documentation/Splunk/8.2.2/Installation/HowtoupgradeSplunk

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Mukunda7 

If your issue is resolved please accept the answer. 

I will also request you to upvote the answers and comments here that you found useful

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @Mukunda7 

There is no definitive guide other than splunk docs, you can start with following links and dive through it based on your existing setup.

https://docs.splunk.com/images/d/d3/Splunk_upgrade_order_of_ops.pdf

https://docs.splunk.com/Documentation/Splunk/8.2.2/Installation/HowtoupgradeSplunk

--

An upvote would be appreciated if this reply helps!

Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...