Current State : We have below Splunk instances running 6.5.2 version
The Indexer also shared role of DMC/LM/DS.
The plan is to
so expected Future State would be :
I have two main queries,
1: The main thing is to have quick access to technical help in case anything goes as planned. There is no "magic playbook" or anything like that. Expect at least 1 big head-scratcher along the way. Be sure that you are in community slack.
2: Upgrade all the apps on the old indexer to match the ones on the new indexers. The only features that will be incompatible are write
features but the old indexer will be read-only
. The only exception is the SRS features described here (make sure that you use legacy settings):
https://www.google.com/url?sa=t&source=web&rct=j&url=https://static.rainfocus.com/splunk/splunkconf1...