Hi @chenfan , the impact on license is null because you pay license based on the logs that are daily indexed, so probably they will be the same. About feature, you have many additional feature in t...
See more...
Hi @chenfan , the impact on license is null because you pay license based on the logs that are daily indexed, so probably they will be the same. About feature, you have many additional feature in the new Splunk version, you can read at the links I shared to see the new features and the removed features. Put very much attention to the migration path and follow every step (even if it's very long!), because between 7 and 9 versions there were many structural changes (Pyton, mongodb, html, etc...). Then you have also to upgrade all the apps, because some of them aren't compatible with the old app versions. Then remember thet there's an orden in upgrading: Cluster Manager, Search Heads, Indexers, Other Splunk Servers (e.g. Deployment Server or Monitoring Console), Heavy Forwarders Universal Forwarders; and this order must be maintained for each upgrade level (7->8 all the steps, 8->9 all the steps). Last hint: plan all the steps in a document to be sure that you aren't forgotting any step. As I said, it will be a very long job, and it could be a good idea, to engage a certified Splunk Architect in the design phase and eventually also in the execution phase. Ciao. Giuseppe