Splunk Enterprise Security

Splunk Enterprise upgrade: Does Enterprise Security version need compatibility with old and new versions?

a_kearney
Path Finder

I am looking to upgrade Splunk Enterprise from 6.6.9 to 8.0.x. I understand this will take at least one intermediary step to Splunk 7.x.

Splunk Enterprise Security 4.7.6 is also installed on the deployment and will require updating to remain compatible. The plan is to end up with SES 6.0.x.

It seems that when upgrading SE the SES version should be compatible with the current version of SE and the version to upgrade to. https://docs.splunk.com/Documentation/Splunk/7.1.0/Installation/AboutupgradingREADTHISFIRST

My problem then comes as I can't find a version of SES that is both compatible with 6.6.x/7.0 and 7.1+, according to the matrix on this page: https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/CompatMatrix

Am I interpreting the documentation correctly? And if so what possible workarounds could be used?

Thanks

0 Karma
1 Solution

maraman_splunk
Splunk Employee
Splunk Employee

Hi

ES app upgrade is done just after Core upgrade in that case, see upgrade ES doc. (so when you launch ES setup, you are on a supported combination)
Please make sure you do backups and are reading all the known issues, especially, you may have some files to clean up from old versions

View solution in original post

maraman_splunk
Splunk Employee
Splunk Employee

Hi

ES app upgrade is done just after Core upgrade in that case, see upgrade ES doc. (so when you launch ES setup, you are on a supported combination)
Please make sure you do backups and are reading all the known issues, especially, you may have some files to clean up from old versions

skalliger
Motivator

Splunk 8 with ES 6.0 is not considered stable yet and I'd not advice to use those versions in production, yet.
You might want to consider upgrading to Splunk Enterprise version 7.3.3 with ES 5.3.1 and go to 8.x and ES 6.x at a later point.

Skalli

a_kearney
Path Finder

Thanks.

Do you have a link to where the stable versions are listed so I can keep track?

0 Karma

skalliger
Motivator

Unfortunately not. The stable versions aren't available publicly. 😕

0 Karma

a_kearney
Path Finder

Ahh, at least I know why I didn't find them in the docs while researching!

0 Karma

skalliger
Motivator

Just wanted to let you know that ES 6.1.1 is considered stable now with Splunk Enterprise 8.0.3. 🙂

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...