Installation

Upgrading SPLUNK 6.5.1 to 7.0.3

pfabrizi
Path Finder

I am currently running SPLUNK Enterprise 6.5.1 with ES and we would like to upgrade to ES 5.0 which requires ASPLUNK Enterprise 6.6 or 7.0.

I am looking for recommended upgrade process. I have a license\deployment server, 1 search head with ES, 1 light weight forwarder and 2 indexers.

is there an order for the devices?
should I stop the splunkd from running?
can I just untar the .tgz file to /opt/splunk?

I do have a process that backsup all the custom stanzas and lookup tables.

Thanks!

Tags (1)
0 Karma

p_gurav
Champion

Below are the steps to upgrade:

Also, read docs carefully before upgrading. 🙂

0 Karma

pfabrizi
Path Finder

is there a difference between core splunk tar file and splunk enterprise?

also my forwarder has a folder of /trvapps/splunkforwarder instead of /trvapps/splunk, so how to I tar that file into that folder?

I create a test folder and did a tar -xzf splunk-7xxx.gz from the /trvapps/test folder and it created a splunk folder, so I am guessing when I upgrade I want to be /trvapps if the splunk folder already exists?

Thanks!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...