Deployment Architecture

Has anyone upgraded from a 6.0.X distributed search environment with search head pooling to 6.2.X with search head clustering?

ben_leung
Builder

Has anyone experienced upgrading from a distributed search environment with search head pooling to the new version 6.2 with search head clustering? Tips and pointers would be appreciated.

0 Karma

wsnyder2
Path Finder

Hello, I am in the same boat. Just upgraded our search heads from 6.1.4 to 6.2.2 and want to change from SHPool to SHCluster. The Splunk docs regarding migration are vague. It sounds like new splunk instances are required (?) and you migrate configs/app ... Can these be on the same host? or do I need new hosts? Help : - )

0 Karma

ben_leung
Builder

Was told by Splunk support that we need new instances for SHC. It can be on the same host when migrating the files. Have you set up a deployer instance to push apps? We had a lengthy discussions where the deployer was not actually required, but removing it would lead to a lot of responsibilities in managing apps in the SHC.

There are many points to consider while there is a lack of documentation that is very specific/technical from my perspective.

If I were you, I would revert back to 6.1.4, then have new 6.2.2 instances installed and then migrate the needed files.

@Splunk Inc. please have some support for migration/upgrade for pooling to clustering. It would greatly be beneficial to all customers.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Do note, according to http://docs.splunk.com/Documentation/Splunk/6.2.1/Installation/Aboutupgradingto6.2READTHISFIRST there is no migration path from SHP to SHC directly.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...