Installation

What is the best way to upgrade Splunk Enterprise in a non-clustered environment?

Splunker6789
Explorer

What is the best way to upgrade Splunk Enterprise in a non-clustered environment?

Labels (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

Start with confirming your backups. I've not had many problems out of Splunk upgrades, but that doesn't mean you wont.

Then:

Have you read through the upgrade docs?

If you are non-anything (no cluster, all-in-one sort of environment) then you just upgrade using whatever method you originally installed it with (windows is a point-and-click, tar is stop splunk untar then chown the directory again and start, rpm/deb is standard for those tools) .

If you are distributed, there's an order to upgrading the pieces but otherwise the individual installations are as above.

If you cluster, there's a special cluster upgrade process depending on whether you have an indexer cluster or a search head cluster.

That's all in the docs, so I'd say make a backup, test that backup, read through the documentation provided then give it a try. If you get stuck or have specific questions about the upgrade ask again!

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust

Start with confirming your backups. I've not had many problems out of Splunk upgrades, but that doesn't mean you wont.

Then:

Have you read through the upgrade docs?

If you are non-anything (no cluster, all-in-one sort of environment) then you just upgrade using whatever method you originally installed it with (windows is a point-and-click, tar is stop splunk untar then chown the directory again and start, rpm/deb is standard for those tools) .

If you are distributed, there's an order to upgrading the pieces but otherwise the individual installations are as above.

If you cluster, there's a special cluster upgrade process depending on whether you have an indexer cluster or a search head cluster.

That's all in the docs, so I'd say make a backup, test that backup, read through the documentation provided then give it a try. If you get stuck or have specific questions about the upgrade ask again!

0 Karma

Splunker6789
Explorer

Thanks awesome!

0 Karma

ddrillic
Ultra Champion

Keep in mind that in addition to the binaries which are being upgraded, the default directories with the explicit configurations, are being upgraded for each component. So, you would like to be in a position where you can compare the pre-upgrade default configurations with the post-upgrade default configurations - fascinating as it's all explicit.

We flipped out a bit during the upgrade to 6.5.1 - Why does the upgrade to 6.5.1 touch SPLUNK_HOME/etc/system/local?

So, it's a good idea to check whether local files get touched and if so in which way and why.

mattymo
Splunk Employee
Splunk Employee

one at a time, with tarball has never let me down.

- MattyMo
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...