Splunk Enterprise Security

Splunk 6.5.1 and Splunk Enterprise Security 4.5.1: What is upgrade path from Splunk 6.4.0 and ES 4.1.1?

brdr
Contributor

Hi,

I know the order to upgrade Splunk components. But don't totally understand the path to upgrade from Splunk Enterprise 6.4.0 / Splunk Enterprise Security (ES) 4.1.1 to Splunk Enterprise 6.5.1 / ES 4.5.1 on the ES search head only.

Do I need to bring current ES 4.1.1 to Enterprise 6.4.4 first? Then upgrade to ES 4.5.1, then upgrade Enterprise to 6.5.1? Can anyone help? Thank you.

0 Karma
1 Solution

jwelch_splunk
Splunk Employee
Splunk Employee

Upgrade your core to 6.5.1

Then after you restart your search head upgrade to ES4.5.1

If it were me I would wait for 6.5.2 which should be coming soon.

It addresses a bundle replication issue and an ssl performance issue

View solution in original post

0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

Upgrade your core to 6.5.1

Then after you restart your search head upgrade to ES4.5.1

If it were me I would wait for 6.5.2 which should be coming soon.

It addresses a bundle replication issue and an ssl performance issue

0 Karma

sloshburch
Splunk Employee
Splunk Employee

For posterity, anyone who lands on this in the future may also appreciate @jmulcaster_splunk's post of an order-of-operations diagram with links to relevant documentation to help with upgrade planning. Check it out and let us know if you find it helpful. What's the order of operations for upgrading Splunk Enterprise?

0 Karma

brdr
Contributor

Thank you.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...