Hello,
I'm using Splunk 7.2.6 and ES 5.2.2 (on a SHC) and I want to upgrade ES to 5.3 on this SHC environment.
According to the install documentation, I did the following :
- install ES 5.2.2 on Master Deployment server (ES was never installed before on the deployer, only on SHC members)
- restart, blabla, then "splunk apply shcluster-bundle"
As long as I already had ES 5.2.2 on SHC members, nothing was changed.
According to the UPGRADE documentation now, I did the following :
- install ES 5.3 on Deployer (via the GUI, as explained)
- restart blabla, splunk apply shcluster-bundle.
And 5.3 was **NOT deployed** on my SHC members, just as I expected.
In fact, as far as I understand Splunk deployment, installing something on the deployer via GUI will install the app (here ES) in etc/apps.
For any app to be deployed by deployer, it has to be present in etc/**shcluster**/apps.
So here is my point : how is it possible for ES to be deployed anywhere if it's only installed in etc/apps ?
Did I miss anything, or is it something missing in the documentation ?
Link to th docs :
Install : https://docs.splunk.com/Documentation/ES/5.3.0/Install/InstallEnterpriseSecuritySHC
Upgrade :
https://docs.splunk.com/Documentation/ES/5.3.0/Install/UpgradeEnterpriseSecuritySHC
Thanks for the help.
Regards.
↧