Splunk SOAR

How to downgrade SOAR to a previous version? 6.3.1 -> 6.2.2

mpc7zh
Explorer

I'm having some issues with my on-prem deployment of Splunk SOAR 6.3.1and would like to revert to 6.2.2. Should I just follow the steps for upgrading even though I'm reverting to a previous version?

https://docs.splunk.com/Documentation/SOARonprem/6.2.2/Install/UpgradeSOARInstance

Labels (3)
0 Karma

mpc7zh
Explorer


The reason I want to revert is because of this known issue:

2024-12-03PSAAS-20901supervisord failing to start on warm standby instance

https://docs.splunk.com/Documentation/SOARonprem/6.3.1/ReleaseNotes/KnownIssues

When SOAR needs to be restarted on our warm standby it fails to start because supervisord can't start. The only workaround I've been able to find is disabling the warm standby so it's a primary. Then restarting SOAR after which I set the server as the warm standby again.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@mpc7zh- Downgrading never works the same way as Upgrade.

Will the commands work?? -> Yes, maybe. But it will break functionalities and stuff. Soar may not work properly. It may even create issues when you upgrade it in the future as well.

 

Maybe Splunk support might be able to help you with this. You can raise a support ticket for it.

 

But my question to you is, why do you need to downgrade in the first place?? Because a lot of time, usually thing that you need to do might be possible even without downgrading the soar.

 

I hope this helps!!! Kindly upvote if it does!!!

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...