Installation Manual

 


Upgrading a forwarder from 2.x to 3.x

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Upgrading a forwarder from 2.x to 3.x

The procedure for upgrading a Splunk forwarder from 2.x to 3.x is identical to that of any Splunk install, with a few additional steps.


Note: This procedure assumes you have set the $SPLUNK_HOME environment variable. To do this, execute the following command (where pathtoSplunk = the path to your Splunk install).


To upgrade a forwarder from 2.x to 3.x

  1. Follow the procedures for upgrading Splunk 2.x to 3.x.
  1. Patch splunkd.xml.
# Go to the directory containing splunkd.xml.  


# Apply the patch for forwarders to splunkd.xml.


  1. Convert config.xml to outputs.conf.
# Go to the TCP directory.


# Execute the following command:


  1. Rename config.xml and to config.xml.old (to have a back-up).
  1. If you have enabled local indexing, add the key indexAndForward=true under the [tcpout] stanza in outputs.conf. If you haven't enabled local indexing, skip this step.
  1. Start Splunk.

Your upgrade is now complete.

This documentation applies to the following versions of Splunk: 3.1.4 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!