Installation

Steps to upgrade an indexer clustering environment from Splunk 6.1.5 to 6.1.8?

rbal_splunk
Splunk Employee
Splunk Employee

We need to upgrade an indexer clustering environment from 6.1.5 to 6.1.8 and we have aCluster Master, 2 Cluster Peers, Three Search Heads, and a Deployment Server. Please provide high level steps.

Labels (3)
0 Karma
1 Solution

rbal_splunk
Splunk Employee
Splunk Employee

Here are the steps that shoudl help upgrade a Clustered environment from 6.1.5 to 6.1.8.

Step 1: Take the backup ($SPLUNK_HOME) of all Splunk components that is Master node, peers node (Indexer 01 and Indexer 02), search heads (1,2,3) and deployment server. Refer http://docs.splunk.com/Documentation/Splunk/6.2.4/Installation/HowtoupgradeSplunk

Step 2: As you are upgrading from 6.1.5 to 6.1.8 (Upgrade to a new maintenance release) you need to follow below steps as suggested in doc (http://docs.splunk.com/Documentation/Splunk/6.1.8/Indexer/Upgradeacluster)

2.0) SHUTDOWN CLUSTER MASTER*
2.1: Upgrade the master node, before running installer stop Splunk (./splunk stop).
(Note: other Splunk components can continue to run i.e. peers node, search heads and deployment server)

2.1.1) START THE CLUSTER MASTER**
2.2: Put the master into maintenance mode with below command
./ splunk enable maintenance-mode

2.3: check is master is in maintenance which below command
./ splunk show maintenance-mode (A returned value of 1 indicates that maintenance mode is on. 0 indicates that maintenance mode is off.)

2.4.0 ) **SHUT DOWN ONE PEER at a Time and finish upgrade on it started it after that and move to 2nd Peer **

2.4 : Stop the peer nodes using ./splunk stop before running installer (repeat same process for other peers as well)

2.5: Upgrade the search heads, before that you need to stop splunk service from all SH01,02 and 03 ? or only on particular box where you plan to ruin install? (Process is one by one upgrade or can we do concurrently?)

2.6: After successful upgrade of all component need to disable the maintain mode with below command ./splunk disable maintenance-mode (For cross verify we can check ./splunk show maintenance-mode)

View solution in original post

rbal_splunk
Splunk Employee
Splunk Employee

Here are the steps that shoudl help upgrade a Clustered environment from 6.1.5 to 6.1.8.

Step 1: Take the backup ($SPLUNK_HOME) of all Splunk components that is Master node, peers node (Indexer 01 and Indexer 02), search heads (1,2,3) and deployment server. Refer http://docs.splunk.com/Documentation/Splunk/6.2.4/Installation/HowtoupgradeSplunk

Step 2: As you are upgrading from 6.1.5 to 6.1.8 (Upgrade to a new maintenance release) you need to follow below steps as suggested in doc (http://docs.splunk.com/Documentation/Splunk/6.1.8/Indexer/Upgradeacluster)

2.0) SHUTDOWN CLUSTER MASTER*
2.1: Upgrade the master node, before running installer stop Splunk (./splunk stop).
(Note: other Splunk components can continue to run i.e. peers node, search heads and deployment server)

2.1.1) START THE CLUSTER MASTER**
2.2: Put the master into maintenance mode with below command
./ splunk enable maintenance-mode

2.3: check is master is in maintenance which below command
./ splunk show maintenance-mode (A returned value of 1 indicates that maintenance mode is on. 0 indicates that maintenance mode is off.)

2.4.0 ) **SHUT DOWN ONE PEER at a Time and finish upgrade on it started it after that and move to 2nd Peer **

2.4 : Stop the peer nodes using ./splunk stop before running installer (repeat same process for other peers as well)

2.5: Upgrade the search heads, before that you need to stop splunk service from all SH01,02 and 03 ? or only on particular box where you plan to ruin install? (Process is one by one upgrade or can we do concurrently?)

2.6: After successful upgrade of all component need to disable the maintain mode with below command ./splunk disable maintenance-mode (For cross verify we can check ./splunk show maintenance-mode)

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...