Installation

does Splunk 4.3.2 supports splunk 6 db artifacts ?

rakesh_498115
Motivator

Hi..

We are planning for a upgrade from splunk 4.3.2 to splunk6 , for the current splunk 4.3.2 is installed on the below mount point

i.e splunk 4.3.2 mount point : /opt/splunk
splunk 4.3.2 db mount point : /opt/splunk/var

Now we are planning to install splunk6 in different mount point say , /opt/splunk6 and share the common db as splunk 4.3.2 . Now we are planning shutdown 4.3.2 and start splunk6. Lets say something gone wrong , and we wanted to rollback to splunk 4.3.2 , then in this case if we turn off splunk6 and enable splunk4.3.2 , will the database works without fail ? or we will loose data ?? i.e splunk 4.3.2 again supports the Splunk 6 database stuff??

Thanks in advance.

Tags (2)
0 Karma

lguinn2
Legend

I don't have a definitive answer, but this seems like a risky idea to me.

There are certainly some differences between the 4.3.2 index files and the 6.0 index files. I don't know whether the differences would be catastrophic for a down rev from 6.0 to 4.3.2, but I wouldn't want to be the admin responsible. I don't know of anyone else who has actually done this, either.

Instead, I think you should build a 6.0 test environment and investigate it thoroughly with your data. If it works well, then I would take a backup of production and upgrade to 6.0 - without any expectation of being able to rollback to 4.3.2...

0 Karma

rakesh_498115
Motivator

Hi .Thanks for the update ..One more thing, if i copy the db of splunk 4.3.2 in to db path of splunk 6 , will it work without any problem ?

0 Karma

sowings
Splunk Employee
Splunk Employee

Usual caveats about data backup, etc, apply.

0 Karma

sowings
Splunk Employee
Splunk Employee

I've upgraded from 4.3 straight to 6; I didn't have any issues.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...