Splunk® Enterprise

Installation Manual

Download manual as PDF

Splunk version 4.x reached its End of Life on October 1, 2013. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Upgrade from 3.x to 4.3

This topic discusses the steps required to upgrade from version 3.x of Splunk to version 4.3. If you currently operate a Splunk deployment based on version 3.4 or earlier, read this topic to find out what to expect and how to do it properly.


Upgrading from version 3 of Splunk to version 4 is a significant, complex undertaking. This is because Splunk versions 4.0 and later have a completely different architecture than Splunk versions 3.x and earlier. The changes between versions 3.x and 4.0 are diverse and far-reaching, and present many challenges during the upgrade process.

For this reason, there is no direct upgrade path from version 3.x to version 4.3. Attempting to upgrade directly from 3.x to 4.3 is unsupported and is strongly discouraged. You should only upgrade to version 4.3 after you have determined that your migration to version 4.0 is stable and complete.

Depending on the complexity of your Splunk deployment, you might want to perform the upgrade from 3.x to 4.0 manually.

Before you begin the upgrade, be sure to back up your Splunk 3.x deployment completely first by using whatever backup tools are available to you.

Upgrade process

To upgrade from Splunk 3.x to Splunk 4.3, you must perform these steps in order:

1. Back up your Splunk 3.x deployment and have it available in case problems occur during the upgrade.

2. Carefully review "What to expect when upgrading to 4.0" in this manual for specifics on the differences between versions, what gets upgraded, what you must upgrade manually, licensing changes and other pertinent information.

3. Upgrade from version 3.x to version 4.0. Be sure to read the important migration notes in the following topics for additional information:

Note: If you choose instead to upgrade Splunk manually from version 3 to version 4.0, read this topic:

4. Confirm that your Splunk deployment works properly on version 4.0.

5. Once you have confirmed that your environment is working properly, upgrade from version 4.0 to 4.3.

About upgrading to 4.3 READ THIS FIRST
Upgrade to 4.3 on UNIX

This documentation applies to the following versions of Splunk® Enterprise: 4.3, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters