Installation

splunk upgrade

vivanv98
Engager

My server has windows version 2016 and it has splunk 7 , now i want to upgrade it to splunk 9 and 2019 version. what should be the flow to upgrade , so that i dont loose any old splunk 7 Data?

Labels (4)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. Splunk 7 is and has been unsupported for quite some time already so if anything goes wrong you might have problems getting help. This upgrade is several years overdue.

2. See the https://docs.splunk.com/Documentation/Splunk/9.1.1/Installation/HowtoupgradeSplunk document for requirements for specific versions (you can change the version of the document in the top right corner). You can upgrade to 9.x from 8.2 or any lower 9.x. So your first "stop" needs to be 8.2. If you see the document version for a 8.2 release, you see that you firstly have to upgrade to 8.0 or 8.1

So your upgrade path should be 7.x -> 8.0.x or 8.1.x -> 8.2.x -> 9.x

vivanv98
Engager

My indexer server is 2016 and splunk 7 is installed there , but somehow OS got crashed , so we have to re-install the OS and after that we will re-install the splunk 7 instance there, and the old Data is present in F Drive as it was configured as such.
so my question is that if i re-install the splunk 7 there and configure it as old version, will the data get reflected in splunk instance?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Ahhhh... So it's not a simple in-place upgrade but rather a restore from a broken installation? (I assume it's an all-in-one instance). It should be doable but it depends on the layout of the original server, on how it was installed, where the configuration was stored and so on. And it's something I'd advise you to go to your friendly local Splunk Partner for help because it's something that requires a bit of experience to do properly and damage your data.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...