Deployment Architecture

Can monitoring console v9.x support search peers v8.1.5 ?

dm1
Contributor

Our monitoring console is also acting as a deployment server.

As per SVD-2022-0608 vulnerability, we need to upgrade our deployment server to v9.x, however, considering its sharing the role of monitoring console as well, I was wondering whether MC supports compability with peers v8.1.5 ?

From the docs, it states

The search head must be at the same or a higher level than the search peers. 

So it looks like it may be possible.

Can someone please advise if there would be any issues with this ?

Tags (2)
0 Karma
1 Solution

gcusello
Legend

Hi @dm1,

in general, if your Deployment Server has to manage many clients it isn't a good idea to use it also for another role, even if the Monitor Console.

Anyway, as you said, the MC is a Search Head and it has to te have a release equal or greter than the Search peers.

There shouldn't be any problem, is this a your doubt before the upgrade or have you an issue?

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
Legend

Hi @dm1,

in general, if your Deployment Server has to manage many clients it isn't a good idea to use it also for another role, even if the Monitor Console.

Anyway, as you said, the MC is a Search Head and it has to te have a release equal or greter than the Search peers.

There shouldn't be any problem, is this a your doubt before the upgrade or have you an issue?

Ciao.

Giuseppe

0 Karma

gcusello
Legend

Hi @dm1,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

gcusello
Legend

Hi @dm1,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

dm1
Contributor

Our Dep Server does'n't have more than 30 clients, so all good.

Yes, it was just my doubt.

0 Karma

gcusello
Legend

Hi @dm1,

in this case there isn't any problem.

Only one final doubt: why do you want to upgrade only DS and not also Search peers?

it's always a best practice to have the same version in all components, the rule of greater version is usually only for special or temporary conditions, usually the version is the same.

Ciao.

Giuseppe

0 Karma

PickleRick
Ultra Champion

I can answer that 🙂

It's way easier to simply quickly upgrade one component due to a CVE than to plan the whole upgrade process of a distributed environment (especially that upgrading to x.0.0 versions is always risky and many admins tend to avoid it; and I can't blame them).

Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...