Currently, we have splunk 6.4 installed on our distributed enviroment. In our enviroment, we have 3 search heads, 2 indexers and 1 master server that act as licensing and deployment server and 1 heavy forwarder. We need to upgrade to Splunk 6.5. The search heads and indexers are in clustered. How do I go ahead ? What would be rollback options.
Hi,
the upgrading process for indexer clusters is described here: http://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Upgradeacluster
When you want do an upgrade, you can not do a rolling-update which means you need to upgrade all instances before bringing them back online.
An upgrade is simply replacing the files in your installation destination (like /opt/splunk/). So, a simple backup would be to backup your splunk directory before upgrading.
Any more questions?
Skalli
Edit: typo
Hi,
the upgrading process for indexer clusters is described here: http://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Upgradeacluster
When you want do an upgrade, you can not do a rolling-update which means you need to upgrade all instances before bringing them back online.
An upgrade is simply replacing the files in your installation destination (like /opt/splunk/). So, a simple backup would be to backup your splunk directory before upgrading.
Any more questions?
Skalli
Edit: typo
I think you should start from reading the docs
https://docs.splunk.com/Documentation/Splunk/6.5.3/Installation/HowtoupgradeSplunk
And here you can find info about downgrading for Unix for example(rollback)
Splunk Enterprise does not provide a means of downgrading to previous versions. If you need to revert to an older Splunk release, uninstall the upgraded version and reinstall the version you want.