We have an indexer, search head, heavy forwarder and universal forwarder. We manage them using Puppet. We are currently running 7.1.1. would like to upgrade them to latest version. These are not clustered. Whats the best way/ best practice to upgrade them??
first the SH, then the Indexer then the HF, and lastly the UF
see here:
http://docs.splunk.com/Documentation/Splunk/7.2.0/Installation/UpgradeyourdistributedSplunkEnterpris...
@jmulcaster_splunk just posted an order-of-operations diagram with links to relevant documentation to help with upgrade planning. Check it out and let us know if you find it helpful. What's the order of operations for upgrading Splunk Enterprise?