Splunk Enterprise

Migrate Index Cluster to New Hardware


Can I have an Index Cluster runnning on both RHEL 7 and RHEL 8?

We are looking to migrate our Splunk estate from RHEL 7 over to RHEL 8. As we have an existing Index Cluster, the plan is

  • Start - RHEL 7 Index Cluster
  • Build the new RHEL 8 Indexers
  • put the cluster into maintenance mode
  • add RHEL 8 indexers into the existing RHEL 7 Index Cluster
  • disable maintenance mode
  • re-balance data accros the RHEL 7 / 8 cluster
  • splunk offline --enforce-counts on RHEL 7 indexer(s) to be removed
  • End - RHEL 8 Index Cluster
Labels (1)
0 Karma


Running RHEL7 and RHEL8 should be fine as long as both run the same version of Splunk.

Your steps are good with a few changes: don't bother with maintenance mode and don't waste time with rebalance.  The off-line step will rebalance the data, anyway.  Be sure to off-line one indexer at a time.

If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

New Cloud Intrusion Detection System Add-on for Splunk

In July 2022 Splunk released the Cloud IDS add-on which expanded Splunk capabilities in security and data ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...