Installation

What is the best way to upgrade Splunk Enterprise in a non-clustered environment?

Splunker6789
Explorer

What is the best way to upgrade Splunk Enterprise in a non-clustered environment?

Labels (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

Start with confirming your backups. I've not had many problems out of Splunk upgrades, but that doesn't mean you wont.

Then:

Have you read through the upgrade docs?

If you are non-anything (no cluster, all-in-one sort of environment) then you just upgrade using whatever method you originally installed it with (windows is a point-and-click, tar is stop splunk untar then chown the directory again and start, rpm/deb is standard for those tools) .

If you are distributed, there's an order to upgrading the pieces but otherwise the individual installations are as above.

If you cluster, there's a special cluster upgrade process depending on whether you have an indexer cluster or a search head cluster.

That's all in the docs, so I'd say make a backup, test that backup, read through the documentation provided then give it a try. If you get stuck or have specific questions about the upgrade ask again!

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust

Start with confirming your backups. I've not had many problems out of Splunk upgrades, but that doesn't mean you wont.

Then:

Have you read through the upgrade docs?

If you are non-anything (no cluster, all-in-one sort of environment) then you just upgrade using whatever method you originally installed it with (windows is a point-and-click, tar is stop splunk untar then chown the directory again and start, rpm/deb is standard for those tools) .

If you are distributed, there's an order to upgrading the pieces but otherwise the individual installations are as above.

If you cluster, there's a special cluster upgrade process depending on whether you have an indexer cluster or a search head cluster.

That's all in the docs, so I'd say make a backup, test that backup, read through the documentation provided then give it a try. If you get stuck or have specific questions about the upgrade ask again!

0 Karma

Splunker6789
Explorer

Thanks awesome!

0 Karma

ddrillic
Ultra Champion

Keep in mind that in addition to the binaries which are being upgraded, the default directories with the explicit configurations, are being upgraded for each component. So, you would like to be in a position where you can compare the pre-upgrade default configurations with the post-upgrade default configurations - fascinating as it's all explicit.

We flipped out a bit during the upgrade to 6.5.1 - Why does the upgrade to 6.5.1 touch SPLUNK_HOME/etc/system/local?

So, it's a good idea to check whether local files get touched and if so in which way and why.

mattymo
Splunk Employee
Splunk Employee

one at a time, with tarball has never let me down.

- MattyMo
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...