Upgrade to a cohosted KV store
Prepare your KV store for upgrade to Splunk Enterprise 10.6 or higher.
Complete the following steps to prepare for and troubleshoot your upgrade.
Prepare for upgrade
Perform a KV store database migration readiness check before upgrading to Splunk Enterprise 10.6 or higher. Complete all of the following steps to prepare for upgrade:
- Ensure your deployment has KV store server version 7.0 or higher. To check what version of KV store you're using and upgrade if necessary, see Upgrade the KV store server version.
-
Ensure that more than 50% of your disk space is available.
- Confirm that the KV store is healthy by checking its status by using the following command in the CLI:
CODE
splunk show kvstore-status - If you are using a clustered deployment, ensure that the cluster is healthy before upgrading your deployment by using the following command:
Confirm the following items in the response:CODE
splunk show shcluster-status --verbose- No nodes are in manual detention mode.
- No nodes are in maintenance mode.
- No rolling upgrades or restarts are in progress.
- The captain is stabilized and not frequently switching.
- Take a backup of the KV store with parallelism, if you have not done so already. For guidance on taking a parallel backup, see Back up and restore the KV store with parallelism.
-
Ensure your KV store can be in read-only mode for the duration of the upgrade, which might take an extended time depending on a number of factors:
-
Upgrade time increases with a high number of collections
-
Upgrade time increases with a larger KV store
-
Upgrade time decreases with high number of CPU cores
-
Upgrade time decreases with disk IOPS (Input/output operations per second)
Note: Premium apps that rely on KV Store writes, such as Enterprise Security and incident reviews or Splunk IT Service Intelligence (ITSI) and glass tables, have degraded functionality during migration. -
-
Prepare for the KV store upgrade to have a temporary impact on both the KV store and your overall Splunk Enterprise deployment while the upgrade is ongoing and the KV store is in read-only mode. The following KV store administrator operations are unavailable during upgrade:
- KV store maintenance mode
- Restarting the KV store
- Resyncing the KV store
- Backing up or restoring the KV store
- Any write operations
Initiate and monitor your upgrade
- To begin your upgrade to a cohosted KV store version 1.0, upgrade to Splunk Enterprise 10.6 or higher and allow the KV store to upgrade automatically. For more guidance about upgrading Splunk Enterprise, see How to upgrade Splunk Enterprise.
-
To check the status of your migration to a cohosted KV store, use the following command. Optionally, you can add the
--verboseparameter for more information.CODEsplunk show kvstore-statusWhile your upgrade is in progress, this command returns the following information:
CODEThis member: backupRestoreStatus : Busy migrationStatus : InProgress readOnlyPersistent : 0 status : readOnly storageEngine : wiredTiger versionUpgradeInProgress : 0When your upgrade is complete, this command returns the following information:
CODEThis member: backupRestoreStatus : Ready migrationStatus : Migration_Succeeded status : ready storageEngine : wiredTiger versionUpgradeInProgress : 0 Cohosted KVStore Information: status : ready type : Pdl
Optional: Stop or pause an in-progress upgrade to a cohosted KV store
During upgrade to the cohosted KV store, you cannot restart Splunk Enterprise using the CLI. If you need to pause an in-progress upgrade so you can restart Splunk Enterprise, or stop an in-progress upgrade for any other reason, complete the following steps.
- Stop the upgrade:
CODE
splunk stop kvstore-postgres-migration - Verify that the server version upgrade is stopped:
CODE
splunk show kvstore-postgres-migration-status - Clean up the upgrade state:
You can also use this command to clean up the upgrade state for any reason.CODE
curl -sku "admin:$SPLUNK_PASSWORD" \ -X POST \ 'https://127.0.0.1:8089/services/kvstore/migrateToPostgres/cleanup?output_mode=json' - To prevent the upgrade to a cohosted KV store from automatically resuming the next time you start Splunk Enterprise, complete the steps in the next Optional: Postpone the automatic database upgrade to a cohosted KV store before it begins section.
Optional: Postpone the automatic database upgrade to a cohosted KV store before it begins
-
Before upgrading to Splunk Enterprise 10.6, in Splunk Enterprise 10.4 or 10.2, add the following setting to your local server.conf file.The default value ofCODE
[kvstore] postgresMigrateOnStartup = falsepostgresMigrateOnStartupistrue. Setting it to false prevents Splunk Enterprise from automatically starting the database migration at startup. It does not delete KV store data or permanently cancel the database migration. - In a clustered deployment only: From the deployer, push the bundle, and then wait for the resulting rolling restart to complete.
-
In a clustered deployment only: Use the following command to confirm the cluster is healthy.CODE
splunk show shcluster-status --verbose - In a clustered deployment only: Use the following command on every cluster member to verify that
postgresMigrateOnStartup= false.CODEsplunk btool server list kvstore --debug | grep postgresMigrateOnStartup - Upgrade to Splunk Enterprise 10.6. If you have a clustered deployment, complete a rolling upgrade to Splunk Enterprise 10.6. After upgrading each member, verify the following:
-
The member is using Splunk Enterprise 10.6.
-
In the member's server.conf file,
postgresMigrateOnStartup = false. -
Logs contain the phrase
reason="startup_flag_disabled". -
When you run a
splunk show kvstore-statuscommand, yourmigrationStatus = NotStarted. - The KV is ready and all data remains accessible.
-
-
Start Splunk Enterprise 10.6. You should remain on your previous version of KV store.
- To allow the automatic database migration during the next maintenance window, set
postgresMigrateOnStartup=trueon all applicable instances, then restart the instances by following the supported procedure for your deployment architecture.