Deployment Architecture

How to Upgrade Search Head Cluster members from 6.2.1 to 6.2.2

rbal_splunk
Splunk Employee
Splunk Employee

How to Upgrade Search Head Cluster members from 6.2.1 to 6.2.2?

1 Solution

rbal_splunk
Splunk Employee
Splunk Employee

There is yet no published instructions for upgrading a search head cluster. For now you may use the following.
a. Stop all cluster members.
b. Upgrade all members.
c. Stop the deployer.
d. Upgrade the deployer.
e. Restart the deployer.
f. Restart the members.
g. Wait one to two minutes for captain election to complete. The cluster will then start functioning.
Notes:
• All SHC members must be running the same version (down to the maintenance level).
• You can run SHC members against 5.x or 6.x search peers, so it is not necessary to upgrade the indexers at the same time

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

Search head cluster upgrade procedures documented here: http://docs.splunk.com/Documentation/Splunk/6.2.2/DistSearch/UpgradeaSHC

rbal_splunk
Splunk Employee
Splunk Employee

There is yet no published instructions for upgrading a search head cluster. For now you may use the following.
a. Stop all cluster members.
b. Upgrade all members.
c. Stop the deployer.
d. Upgrade the deployer.
e. Restart the deployer.
f. Restart the members.
g. Wait one to two minutes for captain election to complete. The cluster will then start functioning.
Notes:
• All SHC members must be running the same version (down to the maintenance level).
• You can run SHC members against 5.x or 6.x search peers, so it is not necessary to upgrade the indexers at the same time

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...