Installation

What is the best way to upgrade Splunk Enterprise in a non-clustered environment?

Splunker6789
Explorer

What is the best way to upgrade Splunk Enterprise in a non-clustered environment?

Labels (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

Start with confirming your backups. I've not had many problems out of Splunk upgrades, but that doesn't mean you wont.

Then:

Have you read through the upgrade docs?

If you are non-anything (no cluster, all-in-one sort of environment) then you just upgrade using whatever method you originally installed it with (windows is a point-and-click, tar is stop splunk untar then chown the directory again and start, rpm/deb is standard for those tools) .

If you are distributed, there's an order to upgrading the pieces but otherwise the individual installations are as above.

If you cluster, there's a special cluster upgrade process depending on whether you have an indexer cluster or a search head cluster.

That's all in the docs, so I'd say make a backup, test that backup, read through the documentation provided then give it a try. If you get stuck or have specific questions about the upgrade ask again!

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust

Start with confirming your backups. I've not had many problems out of Splunk upgrades, but that doesn't mean you wont.

Then:

Have you read through the upgrade docs?

If you are non-anything (no cluster, all-in-one sort of environment) then you just upgrade using whatever method you originally installed it with (windows is a point-and-click, tar is stop splunk untar then chown the directory again and start, rpm/deb is standard for those tools) .

If you are distributed, there's an order to upgrading the pieces but otherwise the individual installations are as above.

If you cluster, there's a special cluster upgrade process depending on whether you have an indexer cluster or a search head cluster.

That's all in the docs, so I'd say make a backup, test that backup, read through the documentation provided then give it a try. If you get stuck or have specific questions about the upgrade ask again!

0 Karma

Splunker6789
Explorer

Thanks awesome!

0 Karma

ddrillic
Ultra Champion

Keep in mind that in addition to the binaries which are being upgraded, the default directories with the explicit configurations, are being upgraded for each component. So, you would like to be in a position where you can compare the pre-upgrade default configurations with the post-upgrade default configurations - fascinating as it's all explicit.

We flipped out a bit during the upgrade to 6.5.1 - Why does the upgrade to 6.5.1 touch SPLUNK_HOME/etc/system/local?

So, it's a good idea to check whether local files get touched and if so in which way and why.

mattymo
Splunk Employee
Splunk Employee

one at a time, with tarball has never let me down.

- MattyMo
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...