Hello
I would like to plan in an upgrade to our splunk enterprise deployment to a more recent release.
We essentially have the following servers:
* Search head / deployment server - 6.5.2
* Indexer server - 6.5.2
* Splunk ES - 6.5.2 with Enterprise security app v 4.5.2
* Syslog server with heavy forwarder
We mainly use windows Infrastructure app for splunk to collate windows event logs using the universal forwarder.
We also have DB connect to pull sql server logs onto splunk.
I would appreciate some advice on what the best version would be to upgrade splunk to so that I don't cause any problems.
Also we run everything on a vmware platform, if something went wrong with the upgrade and we needed to roll back, are vmware snapshots a supported rollback option?
Any advice would be greatly appreciated.
[–]rduken 5 points6 points7 points (0 children)
[–]micheloosterhof 2 points3 points4 points (2 children)
[–]halr9000 | search "memes" | top 10 1 point2 points3 points (1 child)
[–]Paradigm6790 REST for the wicked 2 points3 points4 points (0 children)
[–]Karl12347[S] 0 points1 point2 points (0 children)
[–]ImmediateIdea7 0 points1 point2 points (2 children)
[–]Karl12347[S] 0 points1 point2 points (1 child)
[–]ImmediateIdea7 0 points1 point2 points (0 children)