Splunk Enterprise

Migrate Index Cluster to New Hardware

boz_8058
Explorer

Can I have an Index Cluster runnning on both RHEL 7 and RHEL 8?

We are looking to migrate our Splunk estate from RHEL 7 over to RHEL 8. As we have an existing Index Cluster, the plan is

  • Start - RHEL 7 Index Cluster
  • Build the new RHEL 8 Indexers
  • put the cluster into maintenance mode
  • add RHEL 8 indexers into the existing RHEL 7 Index Cluster
  • disable maintenance mode
  • re-balance data accros the RHEL 7 / 8 cluster
  • splunk offline --enforce-counts on RHEL 7 indexer(s) to be removed
  • End - RHEL 8 Index Cluster
Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Running RHEL7 and RHEL8 should be fine as long as both run the same version of Splunk.

Your steps are good with a few changes: don't bother with maintenance mode and don't waste time with rebalance.  The off-line step will rebalance the data, anyway.  Be sure to off-line one indexer at a time.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...