Installation

OS Patching Process

willadams
Contributor

Will the following process work for allowing our SPLUNK environment to be patched (Linux patching and not SPLUNK patching). We have an Indexing Cluster with a CM and a single search head and deployment / license server. I have read through the procedures and wanted to clarify in case I incorrectly do this:

Step 1 --> Perform patching on the Cluster Manager

a. Run splunk stop to stop the SPLUNK process
b. Perform the update and restart
c. Post reboot the Cluster Manager will be back online

Step 2 --> Perform patching on the Search Head

a. Run splunk stop to stop the SPLUNK process
b. Perform the update and restart
c. Post reboot the Search head will be back online

Step 3 --> Perform patching on the Deployment / License server

a. Run splunk stop to stop the SPLUNK process
b. Perform the update and restart
c. Post reboot the Search head will be back online

Step 4 --> Perform patching on the Indexer peers

a. Run splunk enable maintenance-mode on the CM
b. Run splunk stop on Indexer 1
c. Perform the update and restart
d. Post reboot Indexer 1 will be back online
e. Run splunk stop on Indexer 2
f. Perform the update and restart
g. Post reboot Indexer 2 will be back online
h. Run splunk disable maintenance-mode on the CM
i. Confirm with splunk show maintenance-mode on the CM

Does this look right?

Tags (1)

gcusello
SplunkTrust
SplunkTrust

Hi @willadams,
there isn't any rule in OS patcing process, the rules you described are to upgrade Splunk.
Anyway, the main rule is to upgrade systems one by one.
I suggest to add only a step, after each restart, to check that Splunk is correctly running.

Only one thing in your environment, it isn't a best practice to have the License Master on the same server of the the Deployment Server (if it manage many Forwarders).
It's better to have a dedicated server or to put it on the Master Node, never on Deployment Server that, if you have more than 50 Forwarders, must be a dedicated server.

Bye.
Giuseppe

Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...