Installation

Questions about upgrading from 6.6.0 to 6.6.3 (Multi-Site Indexer Cluster)?

Thomsonadam
New Member

We are looking to upgrade our entire environment from 6.6.0 to 6.6.3, a software bug keeps causing the Indexers to crash so we have lost an entire site for the past few days. When it comes to upgrading the docs state to wait for the sites replication and search factor to be met, as the indexers have been down for a few days this may take some time. So is it advised to wait for this to happen before upgrading the next site i.e waiting 24 hours before starting to upgrade the second site? Will having each site on different versions cause any issues, or having one site on a different version to the Cluster Master or Search Heads?

Labels (3)
0 Karma

jkat54
SplunkTrust
SplunkTrust

The docs for clustered environment upgrades state that you can do one site at a time in a multisite cluster and that as long as you stay within a "point release" (i.e. 6.3.x to 6.4.x), you can have a mixture of versions during the upgrade.

So I'd upgrade the sites where SF and RF are met, give the bad site time to fixup, and then upgrade it.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Here's a link to the exact document I speak of:

http://docs.splunk.com/Documentation/Splunk/6.6.3/Indexer/Upgradeacluster#Site-by-site_upgrade_for_m...

In fact, if you read a bit further, upgrading to a maintenance release (i.e. 6.3.0 to 6.3.x) can be done in a rolling restart method:

http://docs.splunk.com/Documentation/Splunk/6.6.3/Indexer/Upgradeacluster#Upgrade_to_a_maintenance_r...

However it does caution you to do so as quickly as possible. See the warnings under the Upgrade to a maintenance release.

In the end, I believe you'll be fine because nothing major has changed in the way the buckets are handled between 6.3.0 and 6.3.3 (according to the release notes I've read).

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...