Update: using a new installed Splunk instance made the difference instead of setting it as a MAster thru clustering gui :
new 6.1.3 x64 install;
setting initial password, changing licensing mode, set https and port;
stop new instance;
making changes on server.conf;
untar .tgz file with $SPLUNK_HOME/etc/master-apps/ of the old master;
start new master;
stop all Indexers;
change master_uri on [clustering] stanza of server.conf of all Indexers;
start each Indexer at a time;
I guess how to create a full automated solution using linux´s Heartbeat and a bunch of scripts, for example ;(
... View more