This should work for you :
http://docs.splunk.com/Documentation/Splunk/6.4.2/Indexer/Upgradeacluster#Upgrade_to_a_new_maintenance_release
On another note, if you want to reduce downtime in future, upgrade your search head also to a search head cluster and also add another HF for load balancing the syslog( if it's direct tcp)
... View more
It should be okay just to change it in the operating system, although you will get one day that is not 24 hours because of it, which will make your license accounting temporarily odd.
... View more