Hello,
All of our indexers our on Splunk Cloud, but we have a deployment server that acts as a forwarder for all of our windows servers, and has Splunk Enterprise 7.2.4.2. We need to get this updated to 7.3.
My question is this:
Is it just as simple as running the 7.3 installers and letting the installer do its thing, or do I need to do any steps before to make sure this runs smoothly?
Thanks in advance,
Bob
1) Take the backup of $SPLUNK_HOME/etc/*
2) Stop Splunk $SPLUNK_HOME/bin/splunk stop
3) upgrade splunk
tar -xzf <splunk-7.3 file> -C splunk_directory
4) start splunk and accept license
let me know if this helps!
I think this should be enough to upgrade the server.
HEllo Mayurr98,
I should've mentioned that the deployment server is a Windows2012 server.
Sorry about that oversight.
Bob
1) Take the backup of $SPLUNK_HOME/etc/*
2) Stop Splunk $SPLUNK_HOME/bin/splunk stop
3) upgrade splunk
tar -xzf <splunk-7.3 file> -C splunk_directory
4) start splunk and accept license
let me know if this helps!
I think this should be enough to upgrade the server.
The deployment server we have is a heavy forwarder. We have 29 windows servers (universal forwarders) that forward to the deployment server, and the deployment server forwards to the cloud.
Thanks Mahurr98...I didn't want to believe it was that easy :}
Thanks for the link
is it a universal forwarder or heavy forwarder?