Hi, As the title suggests, I want to "revive" a Splunk lab in our company, which was running on version 8.1.2. My target is version 9.2.10 The lab consists of a full Splunk deployment - it has Cluster Master, multisite Indexer Cluster, Search Head Cluster, SH Deployer, Deployment Server and a few UFs. I have read through some docs about upgrading Splunk, and it appeared to me that I have to through 2 upgrade steps: From 8.1.2 to 9.0 (I am planning to upgrade it to 9.0.4 first), then from 9.0.4 to 9.2.10. Currently Splunk is running in the /home/splunk folder. What I concern most is: How to retain the data of the Indexers? I saw a vid showing the upgrade process, in which they tar the whole $SPLUNK_HOME folder for backup. But that process is quite challenging if you have TBs of data in the $SPLUNK_HOME/var/lib folder, right? Is there any other way to retain data, after upgrading? Also, is there any other thing I should take note of? Any suggestions, recommendations, is welcome
... View more