Installation

Migrate and Upgrade at the same time - best practices?

shushry
New Member

We are planning to migrate from a Splunk 4.3, single server environment to a version 5, scaled new installation (index cluster, etc). Any experiences or recommendation on this? Should we upgrade our existing instance to 5 FIRST, then migrate/expand to a new scaled installation - or install the new environment first, and then import/migrate existing data from the existing 4.3 environment?

Tags (1)
0 Karma

linu1988
Champion

First of all it will not matter in some cases. I would consider below points.
1) Existing implementation plan
2) Whether all the functionality are still available as old versions (Depreciated functionality)
3) Some forwarders doesn't work well even if it's newer version (tested on my own/check compatibility)
4) Upgrading means splunk will migrate settings to newer version of installation (i.e. almost a single step)

Hope you will figure out these things before you go for a full implementation

0 Karma

cgisplunk
Path Finder

Same plans here, from 4.3.6 to the latest 5+.
I reckon upgrade the existing phys v.4 instance to v.5 first, then plan the expansion, plus we also consider going from phys to virtual when on v.5, have a fast storage now that supports the required I/O and capacity.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...