Hello Splunk Community,
We are getting ready to migrate our indexers to new hardware. We would like to take the approach of adding the new indexers into our current cluster after which we'll remove the indexers on the old hardware from the cluster. The only problem is we may be putting RHEL 8 on these new indexers and the old ones have RHEL 7. I know the docs say that the indexers must be on the same OS and OS version, but wondering if we still might be able to mix these two for a short time while we transition from the old to the new hardware. Any insight is appreciated. Thanks!
Thanks, appreciate the response. This would be for a short time, hopefully no longer than a week. I'll post back here if we decide to transition in this way with the result.
This question has been asked before and there was no definite answer based on official docs.
It's true that manual says that all indexers in the cluster should run the same OS and OS version but there is a doubt as to what that (the same version) means.
Since the requirements for Splunk list only the OS as such and all the rest should be provided by the Splunk package, I'd interpret OS version as OS architecture. Which means that all your nodes should be, let's say 64-bit linux boxes. But that's in no way official info.
Having said that - I wouldn't mix the environments (unless for a brief transition period) since it always has a decent chance of introducing maintenance problems.