Upgrade from 3.x to 4.3
This topic discusses the steps required to upgrade from version 3.x of Splunk to version 4.3. If you currently operate a Splunk deployment based on version 3.4 or earlier, read this topic to find out what to expect and how to do it properly.
Upgrading from version 3 of Splunk to version 4 is a significant, complex undertaking. This is because Splunk versions 4.0 and later have a completely different architecture than Splunk versions 3.x and earlier. The changes between versions 3.x and 4.0 are diverse and far-reaching, and present many challenges during the upgrade process.
For this reason, there is no direct upgrade path from version 3.x to version 4.3. Attempting to upgrade directly from 3.x to 4.3 is unsupported and is strongly discouraged. You should only upgrade to version 4.3 after you have determined that your migration to version 4.0 is stable and complete.
Depending on the complexity of your Splunk deployment, you might want to perform the upgrade from 3.x to 4.0 manually.
Before you begin the upgrade, be sure to back up your Splunk 3.x deployment completely first by using whatever backup tools are available to you.
To upgrade from Splunk 3.x to Splunk 4.3, you must perform these steps in order:
1. Back up your Splunk 3.x deployment and have it available in case problems occur during the upgrade.
2. Carefully review "What to expect when upgrading to 4.0" in this manual for specifics on the differences between versions, what gets upgraded, what you must upgrade manually, licensing changes and other pertinent information.
3. Upgrade from version 3.x to version 4.0. Be sure to read the important migration notes in the following topics for additional information:
Note: If you choose instead to upgrade Splunk manually from version 3 to version 4.0, read this topic:
4. Confirm that your Splunk deployment works properly on version 4.0.
5. Once you have confirmed that your environment is working properly, upgrade from version 4.0 to 4.3.
About upgrading to 4.3 READ THIS FIRST
Upgrade to 4.3 on UNIX
This documentation applies to the following versions of Splunk® Enterprise: 4.3, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7