I'm planning an upgrade to the latest version of Splunk Enterprise. What is the high-level order of operations? Is there an intermediate step required if I'm on Splunk 6.5 or earlier? Where do forwarders and premium apps fit in? What docs do I need to refer to help me plan and execute my upgrade?
Glad you asked! We've created a high-level process road map for upgrading Splunk Enterprise, forwarders and apps. This process works for all Splunk Validated Architectures - just skip the components that aren't relevant to your deployment.
This diagram is for planning purposes only. It is not a comprehensive upgrade plan, and does not include technical details for upgrading. Please refer to the linked documentation for the version of Splunk you're upgrading to before you proceed with an upgrade.
Remember these operational best practices for upgrading:
What's your experience? We'd like to hear from you. We'll be updating this graphic as we gather more input.
I would add the following:
Search Head Cluster:
Thanks @bgronvall_splunk! Me thinks you posted this while the image was broken. Now that it's up there, do you feel it captures your details or still missing things?
Would be good to update post to incorporate @bgronvall_splunk's bullets 2, 3, & 6 in the Prepare phase. I think the rest is already there.
Thanks for the input, msykes & bgronvall!
The roadmap does point to the release notes, where the known issues and new features are listed, and to the READ THIS FIRST upgrade considerations topic in docs, which covers functionality changes for new versions and outdated configs. I'll call those specific checks out in the boxes, too.
Let us know if you think of more things to enhance this general roadmap, or something we can add to a future post.
Is there any guide for
troubleshootingfailed upgrades ? And also a best practice for
rollbackthat can be included ?
Hi, @DavidHourani, for now, you can refer to the Splunk Enterprise troubleshooting overview, General troubleshooting issues for distributed search, and Introduction for troubleshooting Splunk Enterprise on Splunk Docs. We'll be posting more upgrade best practices to the validated_best-practice and upgrade tags here on Answers, too, so stay tuned!