Installation

On-Prem Splunk upgrade procedure

EvansB
Path Finder

I need help in getting the step by step process in upgrading Splunk on-prem HF

Labels (1)
Tags (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @EvansB,

the general rule for upgrading is:

  • Search Heads must have a greater version than Indexers,
  • Indexers must have a greater version than connected Heavy Forwarders and Universal Forwarders,
  • Heavy Forwarders must have a greater version than connected Universal Forwarders.

The Step by step procedure depends on your architecture: if you have a Search head Cluster or an Indexer Cluster, there is a prececence in activities.

Then another relevant factor is the starting version: for more infos see at https://docs.splunk.com/Documentation/Splunk/8.2.4/Installation/HowtoupgradeSplunk

For Heavy Forwarders, you have only to perform a simple upgrade, eventually backing up the installation folder.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @EvansB,

the general rule for upgrading is:

  • Search Heads must have a greater version than Indexers,
  • Indexers must have a greater version than connected Heavy Forwarders and Universal Forwarders,
  • Heavy Forwarders must have a greater version than connected Universal Forwarders.

The Step by step procedure depends on your architecture: if you have a Search head Cluster or an Indexer Cluster, there is a prececence in activities.

Then another relevant factor is the starting version: for more infos see at https://docs.splunk.com/Documentation/Splunk/8.2.4/Installation/HowtoupgradeSplunk

For Heavy Forwarders, you have only to perform a simple upgrade, eventually backing up the installation folder.

Ciao.

Giuseppe

isoutamo
SplunkTrust
SplunkTrust
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...