How to upgrade Splunk Enterprise
This topic discusses how to upgrade Splunk Enterprise and its components from one version to another.
In many cases, you upgrade SplunkEnterprise by installing the latest package over your existing installation. On Windows systems, the installer package detects the version that you have installed and offers to upgrade it for you.
Always upgrade Splunk Enterprise with a user account that has administrative privileges.
What's new and awesome in 6.3?
See "Meet Splunk Enterprise 6.3" in the Release Notes for a full list of the new features we've delivered in 6.3.
Review the known issues in the Release Notes for a list of issues and workarounds in this release.
Back up your existing deployment
Always back up your existing Splunk Enterprise deployment before you perform any upgrade or migration.
You can manage your risk by using technology that lets you restore your Splunk Enterprise installation and data to a state prior to the upgrade, whether you use external backups, disk or file system snapshots, or other means. When backing up your Splunk Enterprise data, consider the $SPLUNK_HOME directory and any indexes outside of it.
For more information about backing up your Splunk Enterprise deployment, see "Back up configuration information" in the Admin Manual and "Back up indexed data" in the Managing Indexers and Clusters Manual.
Choose the proper upgrade procedure based on your environment
The way that you upgrade Splunk Enterprise differs based on whether you have a single Splunk instance or multiple Splunk instances connected together. The differences are significant if you have configured a cluster of Splunk instances.
Upgrade distributed environments
If you plan to upgrade a distributed Splunk Enterprise environment, including environments that have one or more search head pools, read "Upgrade your distributed Splunk Enterprise deployment" in the Installation Manual.
Upgrade clustered environments
There are special requirements for upgrading an indexer cluster or a search head cluster.
To upgrade an indexer cluster, see "Upgrade an indexer cluster" in the Managing Indexers and Clusters manual.
To upgrade a search head cluster, see "Upgrade a search head cluster" in the Distributed Search manual.
Those topics have upgrade instructions that supersede the instructions in this manual.
Then, read about important migration information before upgrading
See "About upgrading to 6.3: READ THIS FIRST" for specific migration tips and information that might affect you when you upgrade.
Upgrade from 6.0 and later
Splunk Enterprise supports a direct upgrade from versions 6.0 and later to version 6.3.
Upgrade from 5.0 and earlier
Upgrading directly to version 6.3 from version 5.0 and earlier is not officially supported.
- If you run version 5.0, upgrade to version 6.2 first before attempting an upgrade to 6.3.
- If you run version 4.3, upgrade to version 6.0 first before attempting an upgrade to 6.3.
- If you run a version earlier than 4.3, upgrade to version 4.3 first, then upgrade to version 6.0 before finally attempting an upgrade to 6.3. Read "About upgrading to 4.3 READ THIS FIRST" for specific details on how to upgrade to version 4.3.
Upgrade universal forwarders
Upgrading universal forwarders is a different process than upgrading Splunk Enterprise. Before upgrading your universal forwarders, be sure to read the appropriate upgrade topic for your operating system:
To learn about interoperability and compatibility between indexers and universal forwarders, read "Indexer and universal forwarder compatibility" in the Forwarding Data manual.
Replace lost package manifest files
Splunk installation packages have manifest files that Splunk software needs to run. The manifest files exist in the root of the Splunk installation and end in
-manifest. If the files are not present (for example, if you have deleted them) then Splunk software can not run as it can not verify that it is a valid installation.
If you delete those files in the process of upgrading, or for any reason, you can restore them with the following procedure:
- Download an identical copy of the Splunk installer that you downloaded previously. This copy must be the same version and architecture, as manifest files are specific to each version.
- Extract the files to a directory that is not your existing Splunk installation.
- Copy the files from this directory to the root directory of your Splunk installation.
- Start Splunk Enterprise and confirm that it starts normally.
Install a license
About upgrading to 6.3 - READ THIS FIRST
This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14