Installation

How co I upgrade splunk 4.3.4 to splunk 5, using tar.gz installer?

melonman
Motivator

Hi

I have Splunk 4.3.4 installed using tgz installer on MacOS and Linux.
I want to upgrade them using tar installer to Splunk 5.

Is there automatic upgrade available in tgz installer?
Do I have to manually copy all the configurations in another location and do clean installaion of splunk 5 then copy all configuration back to the splunk 5 installation?

Thank you

Tags (1)
0 Karma
1 Solution

sbrant_splunk
Splunk Employee
Splunk Employee

The process to upgrade is easy. The high-level steps are as follows:

  1. Stop Splunk
  2. Backup your Splunk data (just to be safe)
  3. Untar the appropriate version, overwriting the old version (provided your configuration changes were not entered into a "default" directory, your configurations will not be overwritten)
  4. Start Splunk (you will be asked whether you want to upgrade)
  5. Log in and enjoy your upgraded Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0/Installation/InstallonLinux

View solution in original post

sbrant_splunk
Splunk Employee
Splunk Employee

The process to upgrade is easy. The high-level steps are as follows:

  1. Stop Splunk
  2. Backup your Splunk data (just to be safe)
  3. Untar the appropriate version, overwriting the old version (provided your configuration changes were not entered into a "default" directory, your configurations will not be overwritten)
  4. Start Splunk (you will be asked whether you want to upgrade)
  5. Log in and enjoy your upgraded Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0/Installation/InstallonLinux

sbrant_splunk
Splunk Employee
Splunk Employee

Keep in mind, in a distributed environment, you should upgrade components in the following order:

  1. indexers
  2. search heads
  3. forwarders
0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...