Deployment Architecture

Can monitoring console v9.x support search peers v8.1.5 ?

dm1
Contributor

Our monitoring console is also acting as a deployment server.

As per SVD-2022-0608 vulnerability, we need to upgrade our deployment server to v9.x, however, considering its sharing the role of monitoring console as well, I was wondering whether MC supports compability with peers v8.1.5 ?

From the docs, it states

The search head must be at the same or a higher level than the search peers. 

So it looks like it may be possible.

Can someone please advise if there would be any issues with this ?

Tags (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @dm1,

in general, if your Deployment Server has to manage many clients it isn't a good idea to use it also for another role, even if the Monitor Console.

Anyway, as you said, the MC is a Search Head and it has to te have a release equal or greter than the Search peers.

There shouldn't be any problem, is this a your doubt before the upgrade or have you an issue?

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dm1,

in general, if your Deployment Server has to manage many clients it isn't a good idea to use it also for another role, even if the Monitor Console.

Anyway, as you said, the MC is a Search Head and it has to te have a release equal or greter than the Search peers.

There shouldn't be any problem, is this a your doubt before the upgrade or have you an issue?

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dm1,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dm1,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

dm1
Contributor

Our Dep Server does'n't have more than 30 clients, so all good.

Yes, it was just my doubt.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dm1,

in this case there isn't any problem.

Only one final doubt: why do you want to upgrade only DS and not also Search peers?

it's always a best practice to have the same version in all components, the rule of greater version is usually only for special or temporary conditions, usually the version is the same.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

I can answer that 🙂

It's way easier to simply quickly upgrade one component due to a CVE than to plan the whole upgrade process of a distributed environment (especially that upgrading to x.0.0 versions is always risky and many admins tend to avoid it; and I can't blame them).

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...