Installation

does Splunk 4.3.2 supports splunk 6 db artifacts ?

rakesh_498115
Motivator

Hi..

We are planning for a upgrade from splunk 4.3.2 to splunk6 , for the current splunk 4.3.2 is installed on the below mount point

i.e splunk 4.3.2 mount point : /opt/splunk
splunk 4.3.2 db mount point : /opt/splunk/var

Now we are planning to install splunk6 in different mount point say , /opt/splunk6 and share the common db as splunk 4.3.2 . Now we are planning shutdown 4.3.2 and start splunk6. Lets say something gone wrong , and we wanted to rollback to splunk 4.3.2 , then in this case if we turn off splunk6 and enable splunk4.3.2 , will the database works without fail ? or we will loose data ?? i.e splunk 4.3.2 again supports the Splunk 6 database stuff??

Thanks in advance.

Tags (2)
0 Karma

lguinn2
Legend

I don't have a definitive answer, but this seems like a risky idea to me.

There are certainly some differences between the 4.3.2 index files and the 6.0 index files. I don't know whether the differences would be catastrophic for a down rev from 6.0 to 4.3.2, but I wouldn't want to be the admin responsible. I don't know of anyone else who has actually done this, either.

Instead, I think you should build a 6.0 test environment and investigate it thoroughly with your data. If it works well, then I would take a backup of production and upgrade to 6.0 - without any expectation of being able to rollback to 4.3.2...

0 Karma

rakesh_498115
Motivator

Hi .Thanks for the update ..One more thing, if i copy the db of splunk 4.3.2 in to db path of splunk 6 , will it work without any problem ?

0 Karma

sowings
Splunk Employee
Splunk Employee

Usual caveats about data backup, etc, apply.

0 Karma

sowings
Splunk Employee
Splunk Employee

I've upgraded from 4.3 straight to 6; I didn't have any issues.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...