Installation

What is the best way to upgrade Splunk Enterprise in a non-clustered environment?

Splunker6789
Explorer

What is the best way to upgrade Splunk Enterprise in a non-clustered environment?

Labels (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

Start with confirming your backups. I've not had many problems out of Splunk upgrades, but that doesn't mean you wont.

Then:

Have you read through the upgrade docs?

If you are non-anything (no cluster, all-in-one sort of environment) then you just upgrade using whatever method you originally installed it with (windows is a point-and-click, tar is stop splunk untar then chown the directory again and start, rpm/deb is standard for those tools) .

If you are distributed, there's an order to upgrading the pieces but otherwise the individual installations are as above.

If you cluster, there's a special cluster upgrade process depending on whether you have an indexer cluster or a search head cluster.

That's all in the docs, so I'd say make a backup, test that backup, read through the documentation provided then give it a try. If you get stuck or have specific questions about the upgrade ask again!

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust

Start with confirming your backups. I've not had many problems out of Splunk upgrades, but that doesn't mean you wont.

Then:

Have you read through the upgrade docs?

If you are non-anything (no cluster, all-in-one sort of environment) then you just upgrade using whatever method you originally installed it with (windows is a point-and-click, tar is stop splunk untar then chown the directory again and start, rpm/deb is standard for those tools) .

If you are distributed, there's an order to upgrading the pieces but otherwise the individual installations are as above.

If you cluster, there's a special cluster upgrade process depending on whether you have an indexer cluster or a search head cluster.

That's all in the docs, so I'd say make a backup, test that backup, read through the documentation provided then give it a try. If you get stuck or have specific questions about the upgrade ask again!

0 Karma

Splunker6789
Explorer

Thanks awesome!

0 Karma

ddrillic
Ultra Champion

Keep in mind that in addition to the binaries which are being upgraded, the default directories with the explicit configurations, are being upgraded for each component. So, you would like to be in a position where you can compare the pre-upgrade default configurations with the post-upgrade default configurations - fascinating as it's all explicit.

We flipped out a bit during the upgrade to 6.5.1 - Why does the upgrade to 6.5.1 touch SPLUNK_HOME/etc/system/local?

So, it's a good idea to check whether local files get touched and if so in which way and why.

mattymo
Splunk Employee
Splunk Employee

one at a time, with tarball has never let me down.

- MattyMo
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...