The classic playbook editor will be deprecated in early 2025. Convert your classic playbooks to modern mode.
After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:
This documentation does not apply to the most recent version of Splunk
® SOAR (On-premises).
For documentation on the most recent version, go to
the latest release.
Upgrade path for Splunk SOAR (On-premises) unprivileged installations
Unprivileged deployments of Splunk Phantom or Splunk SOAR (On-premises) have a more streamlined upgrade path than privileged deployments.
Upgrade paths:
- Unprivileged Splunk Phantom deployments running a release earlier than release 4.10.7 must be upgraded incrementally from release to release, until Splunk Phantom release 4.10.7.
- Unprivileged Splunk Phantom deployments running release 4.10.7 can be upgraded directly to Splunk SOAR (On-premises) release 6.2.1, then can upgrade to release 6.2.2.
- Unprivileged Splunk SOAR (On-premises) running a release earlier than release 6.2.1 can be upgraded to Splunk SOAR (On-premises) release 6.2.1, and then to release 6.2.2.
All deployments must upgrade to Splunk SOAR (On-premises) 6.2.1 before upgrading to higher releases in order to upgrade the PostgreSQL database. PostgreSQL databases local to the SOAR deployment are updated to PostgreSQL 15.x during the upgrade process. The PostgreSQL database for all clustered deployments, or deployments using an external database must be upgraded manually.
A list of important or breaking changes and the versions where those changes occur is in Splunk SOAR (On-premises) upgrade overview and prerequisites. Review that list before upgrading.
Upgrade path table
Look on the following table to find your currently installed Splunk Phantom or Splunk SOAR (On-premises) release to see your complete upgrade path.
Starting version
|
Path to current version
|
Details
|
4.6.19142
|
- Upgrade to 4.8.24304
- Upgrade to 4.9.39220
- Upgrade to 4.10.7
- Upgrade to 6.2.1
- (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x.
- Upgrade to 6.2.2
|
- Upgrade to 4.8.24304
- Single instance upgrade 4.8 Upgrade an unprivileged Splunk Phantom Cluster
- Cluster upgrade 4.8 Upgrade an unprivileged Splunk Phantom Cluster
- Upgrade to 4.9.39220
- Single instance upgrade 4.9 Upgrade an unprivileged Splunk Phantom Cluster
- Cluster upgrade 4.9 Upgrade an unprivileged Splunk Phantom Cluster
- Upgrade to 4.10.7
- Single instance upgrade 4.10.0 - 4.10.7 Upgrade a single unprivileged Splunk Phantom instance
- Cluster upgrade 4.10.0 - 4.10.7 Upgrade an unprivileged Splunk Phantom Cluster
- Upgrade to 6.2.1
- Single instance upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) cluster
- (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
- See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
- Upgrade to 6.2.2
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
|
4.8.24304
|
- Upgrade to 4.9.39220
- Upgrade to 4.10.7
- Upgrade to 6.2.1
- (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x.
- Upgrade to 6.2.2
|
- Upgrade to 4.9.39220
- Single instance upgrade 4.9 Upgrade an unprivileged Splunk Phantom Cluster
- Cluster upgrade 4.9 Upgrade an unprivileged Splunk Phantom Cluster
- Upgrade to 4.10.7
- Single instance upgrade 4.10.0 - 4.10.7 Upgrade a single unprivileged Splunk Phantom instance
- Cluster upgrade 4.10.0 - 4.10.7 Upgrade an unprivileged Splunk Phantom Cluster
- Upgrade to 6.2.1
- Single instance upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) cluster
- (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
- See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
- Upgrade to 6.2.2
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
|
4.9.39220
|
- Upgrade to 4.10.7
- Upgrade to 6.2.1
- (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x.
- Upgrade to 6.2.2
|
- Upgrade to 4.10.7
- Single instance upgrade 4.10.0 - 4.10.7 Upgrade a single unprivileged Splunk Phantom instance
- Cluster upgrade 4.10.0 - 4.10.7 Upgrade an unprivileged Splunk Phantom Cluster
- Upgrade to 6.2.1
- Single instance upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) cluster
- (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
- See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
- Upgrade to 6.2.2
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
|
4.10.0 - 4.10.6
|
- Upgrade to 4.10.7
- Upgrade to 6.2.1
- (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x.
- Upgrade to 6.2.2
|
See:
- Upgrade to 4.10.7
- Single instance upgrade 4.10.0 - 4.10.7 Upgrade a single unprivileged Splunk Phantom instance
- Cluster upgrade 4.10.0 - 4.10.7 Upgrade an unprivileged Splunk Phantom Cluster
- Upgrade to 6.2.1
- Single instance upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) cluster
- (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
- See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
- Upgrade to 6.2.2
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
|
4.10.7
|
- Upgrade to 6.2.1
- (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x.
- Upgrade to 6.2.2
|
- Upgrade to 6.2.1
- Single instance upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) cluster
- (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
- See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
- Upgrade to 6.2.2
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
|
5.0.1 - 6.1.0
|
- Upgrade to 6.2.1
- (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x.
- Upgrade to 6.2.2
|
- Upgrade to 6.2.1
- Single instance upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) cluster
- (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
- See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
- Upgrade to 6.2.2
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
|
6.1.1
|
- (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x.
- (Conditional) If you upgraded your external PostgreSQL database to 15.x in the previous step, then upgrade to 6.2.2.
- (Conditional) If you are using the embedded PostgreSQL database in your Splunk SOAR (On-premises) deployment, then upgrade to 6.2.1.
- Upgrade to 6.2.2
|
- (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
- See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
- (Conditional) If you upgraded your external PostgreSQL database to 15.x in the previous step, then upgrade to 6.2.2.
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
- (Conditional) If you are using the embedded PostgreSQL database, upgrade to 6.2.1
- Single instance upgrade to 6.2.1 Upgrade a Splunk SOAR (On-premises) instance
- Upgrade to 6.2.2
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
|
6.2.0
|
- (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x.
- (Conditional) If you upgraded your external PostgreSQL database to 15.x in the previous step, then upgrade to 6.2.2.
- Upgrade to 6.2.2
|
- (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
- See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
- (Conditional) If you upgraded your external PostgreSQL database to 15.x in the previous step, then upgrade to 6.2.2.
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
- Upgrade to 6.2.2
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
|
6.2.1
|
- (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x.
- Upgrade to 6.2.2
|
- (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
- See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
- Upgrade to 6.2.2
- Single instance upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) instance
- Cluster upgrade to 6.2.2 Upgrade a Splunk SOAR (On-premises) cluster
|
Example
To upgrade from Splunk Phantom release 4.6 to Splunk SOAR (On-premises) 6.2.2:
- Upgrade your Splunk Phantom to release 4.8.24304
- Upgrade Splunk Phantom to release 4.9.39220
- Upgrade Splunk Phantom to release 4.10.7.63984
- Upgrade to Splunk SOAR (On-premises) release 6.2.1
- Upgrade to Splunk SOAR (On-premises) release 6.2.2
Feedback submitted, thanks!