Installation

Upgrading to 4.0

aoates
Splunk Employee
Splunk Employee

Our production instance is on a Linux machine with dual quad core (8 available cores) @ 2.5 GHz and 8GB of physical memory. The total size of the installation is right on the 1TB mark.

1) Based on the size of the DB / Log data how long can we anticipate 3.4.13 to 4.0.10 upgrade to take.

2) What growth for index data can we expect during this? If necessary we can lower our retention configuration so that we don’t run out of space.

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I'm wondering why you'd be going to 4.0.10, instead of 4.1.2.

0 Karma

Mick
Splunk Employee
Splunk Employee

During migration, there are no changes applied to the DB files, so that is not a factor in determining how long a migration will take.

The actual migration itself is very quick, and it should take any longer than installing a new instance or a maintenance release upgrade. What will take time is understanding how the migration will change how you use Splunk, testing it beforehand so you're familiar with the process and re-building any custom dashboards that you have created in the 3.x world.

There will be no increase in the amount of data indexed to your default index unless you specifically add more data sources. Splunk may log and index more internal data than it did before, but the size of the internal indexes is controlled by the default settings and they shouldn't grow any larger than usual.

wwhitener
Communicator

This technically depends. On my upgrade, when I set the SPLUNK_DB variable, it changed the data directory to handle 4.2.2 and after that--even if NO data had been indexed in 4.2.2--3.4.5 threw cookies at the data and it was unrecoverable.

Our upgrade took about 4 hours too.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...