Installation

How do we upgrade our 3 indexer cluster to a 4 indexer cluster with the latest Splunk version and migrate the old data?

athorat
Communicator

We have a distributed clustered environment and need to upgrade it to the latest version.
The plan is to install the latest version on a new set of physical servers.
How do we migrate the old data from the existing infrastructure (3 indexer cluster) to the new 4 indexer cluster.

Labels (2)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

If you can, your easiest solution would be run both clusters in parallel and utilize hybrid / distributed search to search the new and old clusters. Once your data is aged out, you can decommission the old clusters.

Another option would be to bring the new members into the cluster, up the REP factor and Search factor to balance across to the new members. Then decommission the older servers from the cluster..

0 Karma

athorat
Communicator

Thanks for the reply @esix

Thats a good option to run both servers in to parallel but if we decommission the old servers how about the users reports extracted fields, dashboards and other data.

How do we have those in the new systems.
We have one search head and 3 indexers. Planning to have 2 search heads and 4 indexers.

couple of questions regarding the second option. if we add new members to the cluster and up the rep factor how about the old data from the old servers if they are decommissioned.

If we have to migrate the users, reports, dashboards and alerts, what would be the approach to move them.

Thanks.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...