If i am running Splunnk 6.2.x and ES 3.x using search head pooling, and I upgrade to Splunk 6.3.1 and ES 4.0.1 using search head pooling;
* is this supported
* will this cause problems? performance issues, etc.
Can anyone guess what the impact would be if this were implemented?
Are you using native Splunk SH pooling OR custom?
We are using native sh pooling.
Well, native SH Pooling is not supported by ES 4.0.1, as mentioned by @schose. But SH Cluster is supported (on Linux Platform), so consider migrating to the same.
ES 4.x does not support searchhead pooling
"Splunk Enterprise Security does not support search head pooling."
http://docs.splunk.com/Documentation/ES/4.0.1/Install/DeploymentPlanning
Regards,
Andreas