All Apps and Add-ons

We are currently running Splunk 5.0.4. What are the recommended actions to upgrade Splunk?

corners
New Member

Hi

I'm currently running Splunk version 5.0.4 across 2 servers. One server is acting as the indexer & search head. The other is the heavy forwarder & deployment server. These are running on Windows 2008 R2 platform.
It has been deemed necessary to upgrade the Splunk version.

What is the recommended version to upgrade to from 5.0.4?
Will this version install over the existing version of Splunk installed without effecting any data or reports etc that have been created?
Will any of the universal forwarders require an upgrade also?
We have the S.o.S - Splunk on Splunk app installed currently, would this be affected?

Any help would be greatly appreciated.

Thanks

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi corners,

Upgrading from 5.0.4 to the latest release is supported, but you need to follow this upgrade path:

Upgrade from 5.0.4 to 6.3 first, and then from 6.3 to 6.5.

Of course, always backup before upgrading and always read the important upgrade information and changes first.

http://docs.splunk.com/Documentation/Splunk/6.5.0/Installation/HowtoupgradeSplunk#Upgrade_from_5.0_a...

And you had better upgrade universal forwarders to the same version as your indexer and heavy forwarder.
Hope it helps. Thanks!
Hunter Shen

aaraneta_splunk
Splunk Employee
Splunk Employee

Hi corners,

Just to add to hunters' great answer and to address your question about S.o.S. - Splunk on Splunk:

According the S.o.S Splunkbase page, as of Splunk Enterprise 6.3, this app is End of Life. It has been replaced and superseded by the Distributed Management Console (DMC). But now as of 6.5.0, the DMC is now known as the Monitoring Console.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...