Installation Manual

 


Upgrade to 4.1 on Windows

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Upgrade to 4.1 on Windows

This topic describes the procedure for upgrading your Windows Splunk instance from version 4.0.x to a later version. You can upgrade using the GUI installer, or by running msiexec on the commandline as described in "Install on Windows via the commandline".

Before you upgrade

Make sure you've read this information before proceeding, as well as the following:

Windows app and its inputs are disabled by default

The Windows App was enabled by default in its app.conf file in versions 4.0-4.0.2. Starting in version 4.0.3, it is disabled in this file by default. Read on for important details:

Make sure you specify the same domain user

When upgrading, you must explicitly specify the same domain user that you specified during first time install. If you do not specify the same user, Splunk will default to using the Local System User. If you accidentally specify the wrong user during your installation, use the instructions in these instructions to switch to the correct user before starting Splunk.

Don't change the ports

Changing the management port and/or the HTTP port when upgrading is not supported.

Back your files up

Before you perform the upgrade, we strongly recommend that you back up all of your files, including Splunk configurations, data and binaries. Splunk does not provide a means of downgrading to previous versions; if you need to revert to an older Splunk release, just reinstall it.

Upgrading using the GUI installer

1. Stop Splunk either using the Windows Start menu option or by executing the $SPLUNK_HOME/bin/splunk stop command.

2. Download the new MSI file from the Splunk download page.

3. Double-click the MSI file. The Welcome panel is displayed. Follow the onscreen instructions to upgrade Splunk. For information about each panel, refer to the installation instructions.

4. Splunk will start up by default when you complete the installation.

A log of the changes made to your configuration files during the upgrade is placed in $TEMP$.

Upgrading using the commandline

1. Stop Splunk either using the Windows Start menu option or by executing the $SPLUNK_HOME/bin/splunk stop command.

2. Download the new MSI file from the Splunk download page.

3. Use the instructions in "Install on Windows via the commandline".

4. Depending on your specification, Splunk may start automatically when you complete the installation.

A log of the changes made to your configuration files during the upgrade is placed in $TEMP$.

Start Splunk

On Windows, Splunk is installed by default into \Program Files\Splunk and is started by default.

You can start and stop the following Splunk processes via the Windows Services Manager:

You can also start, stop, and restart both processes at once by going to \Program Files\Splunk\bin and typing

#  splunk [start|stop|restart]

This documentation applies to the following versions of Splunk: 4.1 , 4.1.1 , 4.1.2 , 4.1.3 , 4.1.4 , 4.1.5 , 4.1.6 , 4.1.7 , 4.1.8 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!