Installation

How co I upgrade splunk 4.3.4 to splunk 5, using tar.gz installer?

melonman
Motivator

Hi

I have Splunk 4.3.4 installed using tgz installer on MacOS and Linux.
I want to upgrade them using tar installer to Splunk 5.

Is there automatic upgrade available in tgz installer?
Do I have to manually copy all the configurations in another location and do clean installaion of splunk 5 then copy all configuration back to the splunk 5 installation?

Thank you

Tags (1)
0 Karma
1 Solution

sbrant_splunk
Splunk Employee
Splunk Employee

The process to upgrade is easy. The high-level steps are as follows:

  1. Stop Splunk
  2. Backup your Splunk data (just to be safe)
  3. Untar the appropriate version, overwriting the old version (provided your configuration changes were not entered into a "default" directory, your configurations will not be overwritten)
  4. Start Splunk (you will be asked whether you want to upgrade)
  5. Log in and enjoy your upgraded Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0/Installation/InstallonLinux

View solution in original post

sbrant_splunk
Splunk Employee
Splunk Employee

The process to upgrade is easy. The high-level steps are as follows:

  1. Stop Splunk
  2. Backup your Splunk data (just to be safe)
  3. Untar the appropriate version, overwriting the old version (provided your configuration changes were not entered into a "default" directory, your configurations will not be overwritten)
  4. Start Splunk (you will be asked whether you want to upgrade)
  5. Log in and enjoy your upgraded Splunk.

http://docs.splunk.com/Documentation/Splunk/5.0/Installation/InstallonLinux

sbrant_splunk
Splunk Employee
Splunk Employee

Keep in mind, in a distributed environment, you should upgrade components in the following order:

  1. indexers
  2. search heads
  3. forwarders
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...