About Us

Citrus Consulting Services is the Consulting and the Transformation Services arm of Redington Gulf.

Sunday – Thursday: 9:00AM–6:00PM (Sales), Sunday – Saturday: 24×7 / 365 (Support) E.O#3, Ground Floor, Building 01 Dubai Internet City, P.O Box 501 761 Dubai, UAE (+971) 04 516 1500
(+966) 11 462 5323

Citrus Consulting Services

Splunk Version Upgrade Planning

As new functionalities and features are constantly being added to Splunk, implementing upgrades is not only prudent but essential for businesses. This guide will provide you information on preparatory and execution activities involved in Splunk Version Upgrade.


  1. Perform an inventory version check on Splunk components.
  2. Identify apps/add-ons compatibility with target Splunk enterprise version.
  3. Identify apps/add-ons that need an upgrade.

Prepare for upgrade:

  1. Backup Splunk configuration
  2. Benchmark system health

Perform upgrade: Perform the version upgrade in the following order.

  1. Upgrade the Deployment Server
  2. Upgrade the License Master + Monitoring Console
  3. Upgrade Cluster Master
  4. Upgrade Search Head
  5. Upgrade Indexers

Upgrade Splunk add-ons and applications:

  1. Upgrade add-ons and applications to a version compatible with the target Splunk enterprise version.

Verify the upgrade:

  1. Check that the Splunk apps and add-ons work like they did before the upgrade.
  2. For distributed deployment, use Monitoring Console to verify all Splunk Enterprise components.
  3. Review resource utilization for all components and compare to the benchmarked system health prior to the upgrade.
  4. Confirm all components are available.
  5. Confirm that the license master machine works properly, and all indexers are connected to it.
  6. Confirm that the cluster master operates normally and that cluster peers are connecting properly.
  7. Confirm that the search tier operates normally, and that search and indexers communicate properly.
  8. User the Monitoring Console to verify search head cluster state and individual cluster peer nodes.
  9. Confirm that all indexer cluster nodes are communicating with the cluster master.

Finally, upgrade the Universal forwarder if the existing version is not compatible with the latest version of Splunk enterprise. Don’t forget to perform cleanup after the upgrade.

Priyanka is a technology consultant with a demonstrated history of working in the operations and service industry. A Splunk certified core consultant skilled in Splunk, Linux, DevOps and managing client applications. Priyanka inherently understands that the customer is the single most valuable asset an organization can have, and is driven by the unrelenting pursuit of customer-driven focus, ideals and user experience. She has experience with customers across multiple industries and domains and often aided with expediting their journey to Digital Transformation.

Post a Comment

19 − 16 =