Splunk Upgrade sequence 8.0


What is the recommended sequence of upgrading Splunk enterprise to 8.0?
Should i upgrade all apps& add-ons first and then Splunk Enterprise or vice-versa?

Normally in 7.x.x version i'd done first enterprise and then apps-addons, however this link says different,

Also evaluating some apps documents, it states for some apps you need to have Splunk 8.0 first and then upgrade the app, confused!

Labels (3)
0 Karma


Beyond that, follow the instructions you have. Upgrade apps first, unless they require Splunk 8.x; upgrade those apps after upgrading Splunk.

If this reply helps you, Karma would be appreciated.


Hi @sarwshai,
from which version are you upgrading?
if from 7.0.x (or higher) you can directly upgrade to 8, otherwise you have to pass by an intermediate version (for more details see at ).

Anyway, the fist step is to check Apps compatibility: to perform this, install the "Splunk Platform Upgrade Readiness App"
( ) that gives you an overview on the compatibility of each apps to upgrade.

Then follow the instructions at :
In few words, this is the sequence:

  • Master Node
  • Search Heads
  • indexers
  • Heavy Forwarders

For each kind of system, before Splunk and then Apps.

Remember to force the use of Python3 for each system ( ).


Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...