Hi @spisiakmi Wow, Splunk 4! I dont really know where to start with this one, but what I would say is this sort of thing should probably be done with the assistance of Splunk Professional Services ...
See more...
Hi @spisiakmi Wow, Splunk 4! I dont really know where to start with this one, but what I would say is this sort of thing should probably be done with the assistance of Splunk Professional Services (PS). There are so many questions and caveats here. The only "off the shelf" supported option would be to go through the official supported upgrade path for each version as @PrewinThomas has mentioned - but then you also need to balance that with the version of OS that each version is on (e.g. when do you move it from Server 2016 to 2022 and continue the upgrade path). There are also factors like how many indexers you have and what the rest of the environment looks like, how does data get in to Splunk, and how would you manage the upgrade of any forwarders in the estate? There are a number of places in the upgrade journey where the structure of buckets changes. e.g. around 4.1/4.2 there are changes, then again at 7.2 and 8.x which is why the upgrade process is place. Therefore I wouldnt recommend just copying them from the old to the new infrastructure. Depending on the volume of data, one option might be to freeze out the data from your old infra and thaw it out into your new infra. This way the relevant changes are managed by Splunk. According to the docs it is possible to thaw pre 4.2 data into Splunk 9.x - however there are warning about different architecture (is your Windows Server 2016 on 64-bit architecture?). Would you be looking to change the Splunk architecture (e.g utilise clustering) on the new infra? Ultimately there are a number of ways to do this, but I would strongly suggest speaking to a Splunk Partner and/or Splunk Professional Services to get this planned out. Lastly - In order to upgrade from Splunk 4 using the upgrade path, you will need lots of old versions which are no longer publicly available, so you will need to see if support can provide these, however I believe this may be unlikely without PS involvement. Did this answer help you? If so, please consider: Adding karma to show it was useful Marking it as the solution if it resolved your issue Commenting if you need any clarification Your feedback encourages the volunteers in this community to continue contributing