Splunk Enterprise

Upgrade from Splunk Enterprise 9.2.x to 9.3 or 9.4?

SplunkNinja
Path Finder

My environment is currently on the Splunk Enterprise 9.2.x track and support will end on Jan 31 2026.  I wish to upgrade to either Splunk Enterprise 9.3 or 9.4.  Is there any reason to prefer one of these versions (other than support longevity) over the other?

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @SplunkNinja 

There are a whole load of improvements and new features in 9.4 which you might want to take advantage of.

https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/release-notes/9.4/whats-new/w...

Also, you might find that some apps on Splunkbase stop supporting older version of Splunk and focus their new features to newer versions. 

Unless an essential App you use mandates 9.3 compatibility, I would personally always target the newest stable major/minor version for an upgrade  - coming from an older version (9.2.x) to gain the maximum benefit in features, stability, and support lifespan you would be better with 9.4.

Have you considered 10.0? Is there any reason you dont want to move to 9.4/10.0?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

 

PickleRick
SplunkTrust
SplunkTrust

Go through the release notes, compatibility matrix and system requirements. For example at one customer's site I'm for now stuck at 9.2.x due to an underlying OS on which newer releases are not supported.

Also newer versions _might_ be a bit more resource-hungry.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...