Splunk Version Upgrade Planning
As new functionalities and features are constantly being added to Splunk, implementing upgrades is not only prudent but essential for businesses. This guide will provide you information on preparatory and execution activities involved in Splunk Version Upgrade.
- Perform an inventory version check on Splunk components.
- Identify apps/add-ons compatibility with target Splunk enterprise version.
- Identify apps/add-ons that need an upgrade.
Prepare for upgrade:
- Backup Splunk configuration
- Benchmark system health
Perform upgrade: Perform the version upgrade in the following order.
- Upgrade the Deployment Server
- Upgrade the License Master + Monitoring Console
- Upgrade Cluster Master
- Upgrade Search Head
- Upgrade Indexers
Upgrade Splunk add-ons and applications:
- Upgrade add-ons and applications to a version compatible with the target Splunk enterprise version.
Verify the upgrade:
- Check that the Splunk apps and add-ons work like they did before the upgrade.
- For distributed deployment, use Monitoring Console to verify all Splunk Enterprise components.
- Review resource utilization for all components and compare to the benchmarked system health prior to the upgrade.
- Confirm all components are available.
- Confirm that the license master machine works properly, and all indexers are connected to it.
- Confirm that the cluster master operates normally and that cluster peers are connecting properly.
- Confirm that the search tier operates normally, and that search and indexers communicate properly.
- User the Monitoring Console to verify search head cluster state and individual cluster peer nodes.
- Confirm that all indexer cluster nodes are communicating with the cluster master.
Finally, upgrade the Universal forwarder if the existing version is not compatible with the latest version of Splunk enterprise. Don’t forget to perform cleanup after the upgrade.