Hi,
the upgrading process for indexer clusters is described here: http://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Upgradeacluster
When you want do an upgrade, you can not do a rolling-update which means you need to upgrade all instances before bringing them back online.
An upgrade is simply replacing the files in your installation destination (like /opt/splunk/). So, a simple backup would be to backup your splunk directory before upgrading.
splunk stop on your master
splunk stop on Indexers and Search Heads
Upgrade your master (http://docs.splunk.com/Documentation/Splunk/6.5.2/Installation/Upgradeto6.5onUNIX)
replace files from the release in your installation directory on your master (e.g. tar zxf splunk-6.x.x-.tgz -C /opt/)
splunk start on your master, confirm the migration and upgrade process, accept license if needed.
enable the maintenance-mode on your master
Repeat the upgrade step on all indexers and search heads
after all peers have been upgraded and started successfully, disable the maintenance-mode
all peers must be on the same maintenance level (e.g. 6.5.2) and must not be a higher version than your master.
Any more questions?
Skalli
Edit: typo
... View more