Installation

Upgrading SPLUNK 6.5.1 to 7.0.3

pfabrizi
Path Finder

I am currently running SPLUNK Enterprise 6.5.1 with ES and we would like to upgrade to ES 5.0 which requires ASPLUNK Enterprise 6.6 or 7.0.

I am looking for recommended upgrade process. I have a license\deployment server, 1 search head with ES, 1 light weight forwarder and 2 indexers.

is there an order for the devices?
should I stop the splunkd from running?
can I just untar the .tgz file to /opt/splunk?

I do have a process that backsup all the custom stanzas and lookup tables.

Thanks!

Tags (1)
0 Karma

p_gurav
Champion

Below are the steps to upgrade:

Also, read docs carefully before upgrading. 🙂

0 Karma

pfabrizi
Path Finder

is there a difference between core splunk tar file and splunk enterprise?

also my forwarder has a folder of /trvapps/splunkforwarder instead of /trvapps/splunk, so how to I tar that file into that folder?

I create a test folder and did a tar -xzf splunk-7xxx.gz from the /trvapps/test folder and it created a splunk folder, so I am guessing when I upgrade I want to be /trvapps if the splunk folder already exists?

Thanks!

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...