Installation

What is the best way to upgrade Splunk Enterprise in a non-clustered environment?

Splunker6789
Explorer

What is the best way to upgrade Splunk Enterprise in a non-clustered environment?

Labels (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

Start with confirming your backups. I've not had many problems out of Splunk upgrades, but that doesn't mean you wont.

Then:

Have you read through the upgrade docs?

If you are non-anything (no cluster, all-in-one sort of environment) then you just upgrade using whatever method you originally installed it with (windows is a point-and-click, tar is stop splunk untar then chown the directory again and start, rpm/deb is standard for those tools) .

If you are distributed, there's an order to upgrading the pieces but otherwise the individual installations are as above.

If you cluster, there's a special cluster upgrade process depending on whether you have an indexer cluster or a search head cluster.

That's all in the docs, so I'd say make a backup, test that backup, read through the documentation provided then give it a try. If you get stuck or have specific questions about the upgrade ask again!

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust

Start with confirming your backups. I've not had many problems out of Splunk upgrades, but that doesn't mean you wont.

Then:

Have you read through the upgrade docs?

If you are non-anything (no cluster, all-in-one sort of environment) then you just upgrade using whatever method you originally installed it with (windows is a point-and-click, tar is stop splunk untar then chown the directory again and start, rpm/deb is standard for those tools) .

If you are distributed, there's an order to upgrading the pieces but otherwise the individual installations are as above.

If you cluster, there's a special cluster upgrade process depending on whether you have an indexer cluster or a search head cluster.

That's all in the docs, so I'd say make a backup, test that backup, read through the documentation provided then give it a try. If you get stuck or have specific questions about the upgrade ask again!

0 Karma

Splunker6789
Explorer

Thanks awesome!

0 Karma

ddrillic
Ultra Champion

Keep in mind that in addition to the binaries which are being upgraded, the default directories with the explicit configurations, are being upgraded for each component. So, you would like to be in a position where you can compare the pre-upgrade default configurations with the post-upgrade default configurations - fascinating as it's all explicit.

We flipped out a bit during the upgrade to 6.5.1 - Why does the upgrade to 6.5.1 touch SPLUNK_HOME/etc/system/local?

So, it's a good idea to check whether local files get touched and if so in which way and why.

mattymo
Splunk Employee
Splunk Employee

one at a time, with tarball has never let me down.

- MattyMo
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...