Installation

In what order do we upgrade our search head, indexer, deployment server, and heavy forwarder from Splunk 6.2.2. to 6.4?

brdr
Contributor

Hi,

We are upgrading all of our Splunk components from Splunk 6.2.2 to 6.4. Presently, we are NOT in a distributed environment. We have 4 (1 Search Head, 1 Indexer, 1 Deployment Server, 1 Heavy Forwarder) primary servers and a whole set of hosts with universal forwarders. The License Manager is installed on the SH.

What is recommended pecking order to upgrade the 4 servers above?

Thx

Labels (4)
0 Karma
1 Solution

javiergn
Super Champion

First thing you need to do is to read the following two docs:

http://docs.splunk.com/Documentation/Splunk/latest/Installation/Aboutupgradingto6.4READTHISFIRST
http://docs.splunk.com/Documentation/Splunk/6.4.0/ReleaseNotes/KnownIssues#Upgrade_issues

In terms of steps:
1. Test your apps and make sure they are compatible with 6.4
2. Upgrade Deployment Server (disable it first, then upgrade, do not restart it yet)
3. Upgrade Search Heads
4. Upgrade Indexers (once completed you can now restart your deployment server)
5. Upgrade Forwarders

More info here:
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...

View solution in original post

javiergn
Super Champion

First thing you need to do is to read the following two docs:

http://docs.splunk.com/Documentation/Splunk/latest/Installation/Aboutupgradingto6.4READTHISFIRST
http://docs.splunk.com/Documentation/Splunk/6.4.0/ReleaseNotes/KnownIssues#Upgrade_issues

In terms of steps:
1. Test your apps and make sure they are compatible with 6.4
2. Upgrade Deployment Server (disable it first, then upgrade, do not restart it yet)
3. Upgrade Search Heads
4. Upgrade Indexers (once completed you can now restart your deployment server)
5. Upgrade Forwarders

More info here:
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/UpgradeyourdistributedSplunkEnterpris...

jmulcaster_splu
Splunk Employee
Splunk Employee

FYI, we've posted an upgrade roadmap with links to relevant documentation to help with upgrade planning. Check it out and let us know if you find it helpful. What's the order of operations for upgrading Splunk Enterprise?

0 Karma

brdr
Contributor

Awesome. Thanks for answer!

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...