I thought that all nodes needed to be on the same OS version because of this: https://docs.splunk.com/Documentation/Splunk/8.2.2/Indexer/Systemrequirements All indexer cluster nodes (manager node, peer nodes, and search heads) must run on the same operating system and version. If the indexer cluster is integrated with a search head cluster, then the search head cluster instances, including the deployer, must run on the same operating system and version as the indexer cluster nodes. Or is that not a hard and fast rule? If it's the case that I can mix OS versions in an indexer cluster, in light of that, do you think it would be best to join the new indexers into the same cluster as the old indexers and let data replicate between them before retiring the old indexers? Or do you think it would be best to go with my original plan of dividing them into two separate clusters, send new data to the new cluster and search across both clusters until the old data ages off? Thanks for the tip about the SH version, if I go with the second option I will need to upgrade that first then.
... View more