Splunk Enterprise

Upgrade Splunk 8.0.0 to 8.2

goldorak
Engager

Hello,

 

I currently have in production Splunk Enterprise 8.0 with Universal and Heavy Forwarder 8.0.

I plan to upgrade to the latest version 8.2.2.

Can I upgrade :

1. Upgrade Splunk Enterprise servers (Master, Indexer, Search Head, Deployment, Licence server) first and then Forwarder later

2. Upgrade Forwarders first and Splunk Enterprise after

3. Both Splunk Enterprise and Forwarders at the same time

Labels (1)
0 Karma
1 Solution

shivanshu1593
Builder

Hello @goldorak ,

Suggested order for the upgrade is:

1.  Search heads, deployers, Deployment servers

2. Cluster master

3. Indexers

4. Forwarders.

To see if you should upgrade the forwarders before or after Indexers and rest of the components, I'd advise you to go through the compatibility matrix. In some versions, a higher version of HF/UF won't send metrix data to Indexers. That won't happen in your case (since you're upgrading from 8 to 8.2, where forwarders and Indexers are compatible with each other for both event and metrics data), so you're free to upgrade forwarders before everything or at the end.

https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

Also, SHs must run the same or later versions than search peers (Indexers), search peers must run the same versions. Also, take care of metrics index, if you haven't created one yet.

https://docs.splunk.com/Documentation/Splunk/8.2.2/Indexer/Systemrequirements

Let me know if this helps.

Thanks,

S

 

***If this helped, please accept it as a solution. It helps others to find the solution for similar issues quickly.***

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

View solution in original post

shivanshu1593
Builder

Hello @goldorak ,

Suggested order for the upgrade is:

1.  Search heads, deployers, Deployment servers

2. Cluster master

3. Indexers

4. Forwarders.

To see if you should upgrade the forwarders before or after Indexers and rest of the components, I'd advise you to go through the compatibility matrix. In some versions, a higher version of HF/UF won't send metrix data to Indexers. That won't happen in your case (since you're upgrading from 8 to 8.2, where forwarders and Indexers are compatible with each other for both event and metrics data), so you're free to upgrade forwarders before everything or at the end.

https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

Also, SHs must run the same or later versions than search peers (Indexers), search peers must run the same versions. Also, take care of metrics index, if you haven't created one yet.

https://docs.splunk.com/Documentation/Splunk/8.2.2/Indexer/Systemrequirements

Let me know if this helps.

Thanks,

S

 

***If this helped, please accept it as a solution. It helps others to find the solution for similar issues quickly.***

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

rasikmhetre
Explorer

how do we upgrade License Master, because the moment license master goes down I am sure our application will ingest more than 500MB of data within a minute into splunk

Tags (2)
0 Karma

nunoaragao
Path Finder

Where does the License Manager fit this picture ?

Is License Manager 8.0 compatible with 8.2 Indexing layer ?
Or does it need to be upgraded at the same time as Indexers ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...