About upgrading to 10.6 READ THIS FIRST
Read about changes in behavior to note for Splunk Enterprise and Splunk Universal Forwarder when you upgrade to version 10.6.
Lower or higher versions of this topic might present different information than the information for your target version. Use the Version drop-down list to choose the product version to which you're upgrading.
Administrators and advanced users can review changes to the .conf and .conf.spec files by using the Compare feature on different branches of the files in the jewnix/splunk-spec-files GitHub repository. Splunk thanks David Twersky (jewnix) for providing and maintaining this repository, and links to its contents with his permission.
For general instructions on how to upgrade Splunk Enterprise, see How to upgrade Splunk Enterprise.
Splunk App and Add-on Compatibility
Not all Splunk apps and add-ons are compatible with Splunk Enterprise version 10.6.
- See the Splunk products version compatibility matrix for information about which versions of Splunk IT Service Intelligence and Splunk Enterprise Security are compatible with this version of Splunk Enterprise.
- You can visit Splunkbase to confirm that your apps and add-ons are compatible with this version.
If your app or add-on is not compatible with version 10.6, consider delaying your upgrade until a compatible version is available.
Key points for upgrading to version 10.6
The following is a list of important items that you must consider before you upgrade Splunk Enterprise and its components. The sections that follow provide supporting details for these key points. Read through all sections in the topic before you begin your upgrade activities.
- Back up all App Key Value Store (KV Store) databases with parallelism and prepare for your deployment to be automatically migrated to a cohosted KV store. For information about the cohosted KV store migration, including the impact to Enterprise Security and Splunk IT Service Intelligence (ITSI), see Upgrade to a cohosted KV store.
- Use the Splunk Products version compatibility matrix to ensure that any premium Splunk apps and add-ons you run are compatible with version 10.6. If they are not, do not upgrade until compatible versions become available.
- See How to upgrade Splunk Enterprise for information on supported upgrade paths to Splunk Enterprise 10.4.
- Splunk supports a direct upgrade from Universal Forwarder (UF) 10.0.x and higher to UF 10.6.
- To upgrade search head or indexer clusters, see Follow specific instructions to upgrade clusters later in this topic.
- If you run Linux machines that use the second extended (ext2) file system, upgrade that file system to third extended (ext3) prior to starting an upgrade.
- If you use Azure remote storage and the config fields
remote.azure.tenant_id/remote.azure.client_id, take one of the following actions before you upgrade:- Add
remote.azure.tenant_id/remote.azure.client_idfields to theencrypt_fieldslist in the[general]stanza of theserver.conf configuration file. - Change the
remote.azure.tenant_id/remote.azure.client_idfields to empty values.
- Add
-
In a clustered environment, the PostgreSQL network ports must be available to all other members, or SPL2 will not be available. For more information, see Network requirements.
Changes that can potentially break Splunk Enterprise installations
There is no supported method for rolling back an installation to a prior release. Follow the guidance for these critical items to avoid breaking your existing installation during an upgrade.
Security change: Certificate authorities no longer issue TLS certificates with both "Server Auth" and "Client Auth" EKUs by March 2027
Applicable components: All
Applicable OSes: All Version introduced: N/ATo enhance security and comply with industry changes, DigiCert and other certificate authorities (CAs) began removing support for the "Client Authentication" Extended Key Usage (EKU) extensions from public transport layer security (TLS) certificates. One such CA that regularly issues certificates for Splunk, DigiCert, will fully remove support by March 1, 2027, and web browser vendors plan to remove support for CAs that continue issuing public CA certificates with this functionality from web browser trust stores.
This is not specifically a breaking change for Splunk platform 10.6, but it affects you and your Splunk Enterprise deployment if you use certificates for inter-Splunk connections that contain both EKU extensions. You must contact the CA who issues your certificates and obtain updated versions that only contain the "Server Authentication" EKU extension before March 1, 2027. For additional information about EKUs, see Third-party Certificate Authorities cease issuing certificates with 'ServerAuth' and 'ClientAuth' EKU Extensions in the Release Notes.
Splunk has removed support for versions 1.0 and 1.1 of the Transport Layer Security (TLS) protocol
Applicable components: Splunk Enterprise
Applicable OSes: All Version introduced: 10.6, 10.4Splunk deprecated support for TLS protocol versions 1.0 and 1.1 for network connections between Splunk components in Splunk Enterprise 10.0 and completely removed support in version 10.4. Additionally, Splunk removed the option to temporarily turn on and use these deprecated protocol versions. Migrate to using TLS version 1.2 or higher for network connections between Splunk components.
Splunk changed the provider verification mode for Federated Search
Applicable components: Splunk Enterprise
Applicable OSes: All Version introduced: 10.6Splunk changed the provider verification mode for Federated Search, which controls how federated search heads respond to remote search heads that run earlier versions of the Splunk platform.
If you use Federated Search for Splunk, upgrade all remote provider deployments to Splunk Enterprise version 10.4 or higher before starting an upgrade of your deployment. Federated searches fail if any remote search head or remote provider deployment runs a version lower than Splunk Enterprise version 10.4.
Splunk removed the binary files that were associated with older versions of the MongoDB database engine
Applicable components: Splunk Enterprise
Applicable OSes: All Version introduced: 10.4Splunk removed the binaries for unsupported versions of the MongoDB database engine from the installation package in Splunk Enterprise 10.4.
Upgrade KV Store to MongoDB engine version 7 or higher before upgrading to Splunk Enterprise version 10.4.
Splunk changed how App Key Value Store (KV Store) uses TLS-related settings in the [kvstore] stanza of the server.conf configuration file
Applicable components: Splunk Enterprise
Applicable OSes: All Version introduced: 10.4Splunk adjusted the logic that determines whether KV Store uses TLS-related settings in the [kvstore] stanza or falls back to similar settings in the [sslConfig] stanza of the server.conf configuration file.
Prior to Splunk platform 10.4, KV Store ignored TLS-related settings under the [kvstore] stanza that were also present in the [sslConfig] stanza. Beginning with Splunk platform 10.4, KV Store uses TLS-related settings that are present in the [kvstore] stanza first. This might cause unintended connection failures due to conflicting protocol configurations.
Review both stanzas in the server.conf file and remove any TLS-related settings under the [kvstore] stanza that you do not specifically use for securing KV Store connections.
Splunk Enterprise no longer lets you run it as the root user by default
Applicable components: Splunk Enterprise
Applicable OSes: *nix Version introduced: 10.2 On *nix machines, Splunk Enterprise no longer lets you run it as the root user by default. When you attempt this, the instance fails to start with an error message to that effect.--run-as-root CLI argument when you start the instance:
$SPLUNK_HOME/bin/splunk start --run-as-root
Splunk Enterprise on Windows no longer lets you install, upgrade, or run it as an administrator-level user
- If the instance runs as the local system user, the installer reconfigures it to run as a local service account.
- If the instance runs as a domain user, the installer halts the installation and directs you to remove that user from the local Administrators group and try the installation again.
- If the instance runs as a local service account, the installer retains that configuration.
Splunk removed support for Secure Hash Algorithm 1 (SHA1) certificate signatures
Applicable components: Splunk Enterprise
Applicable OSes: All Version introduced: 10.4Splunk deprecated support for the usage of certificates with SHA-1 signatures in Splunk platform 10.0 and completely removed support in Splunk platform 10.4. Re-issue and migrate to certificates that use SHA-256 or higher signatures.
Splunk removed older unsupported MongoDB database engine binaries
Applicable components: Splunk Enterprise
Applicable OSes: All Version introduced: 10.4Splunk removed the binaries for unsupported versions of MongoDB, the database engine that powers KV Store, from the installation package in Splunk Enterprise 10.4.
Upgrade KV Store to MongoDB engine version 7 or higher before upgrading to Splunk Enterprise version 10.4.
Splunk changed the capability requirements that you must satisfy to view dashboards that auto-refresh
Applicable components: Splunk Enterprise, Splunk Cloud Platform
Applicable OSes: All Version introduced: 10.4Splunk changed the capability requirements for users who want to view dashboards that refresh automatically. With Splunk platform 10.4, non-administrator users must hold a role that contains the auto_refresh_dashboards capability.
If you have access to the admin or sc_admin accounts on the instance, add the auto_refresh_dashboards capability to a role that you can then grant to users who need to view auto-refreshing dashboards.
Splunk removed jQuery version 2 from the Splunk platform
Applicable components: Splunk Enterprise, Splunk Cloud Platform
Applicable OSes: All Version introduced: 10.4Splunk has fully removed jQuery version 2 (jQuery 2) from the Splunk platform. This means that Splunk deleted the jQuery upgrade admin page, all jQuery libraries with a version of lower than 3, the quarantine framework, and all associated feature flags, including enable_jQuery2 and enable_unsupported_hotlinked_imports. All platform JavaScript now runs on jQuery version 3 and higher. Apps that hotlink jQuery 2 or rely on jQuery 2-specific APIs will no longer function.
- Migrate classic (version 1.0) dashboards to version 1.1 using the dashboard migration tool before starting an upgrade.
- Run App Inspect checks against your apps to identify usage of jQuery 2 and hot-linked library dependencies.
- Migrate app JavaScript to jQuery 3-compatible APIs.
Updated Linux distribution support on Splunk Enterprise affects Edge Processor on Splunk Enterprise support
Applicable components: Splunk Enterprise, Edge Processor on Splunk Enterprise
Applicable OSes: Linux Version introduced: 10.2 Upgrading to Splunk Enterprise 10.2 includes security updates that address specific common vulnerabilities and exposures (CVEs) but also make certain older Linux distributions incompatible with Edge Processor. If you upgrade your data management control plane to Splunk Enterprise 10.2 while edge processors are running on unsupported Linux versions, those edge processors will crash, and data loss can occur. To prevent this, update the operating systems on all management nodes and edge processor instances to a supported Linux version before upgrading to Splunk Enterprise 10.2 on those machines. Refer to the Installation requirements for Edge Processors for the latest list of supported Linux-based operating systems. Operating systems on machines that Edge Processor does not use do not need updates.The Splunk platform uses version 3.13 of the Python runtime environment on Splunk Web
Applicable components: Splunk Enterprise
Applicable OSes: all Version introduced: 10.2 The Splunk platform now uses version 3.13 of the Python runtime environment for Splunk Web functions.The Node.js JavaScript runtime environment has been removed
Applicable components: Splunk Enterprise
Applicable OSes: all Version introduced: 10.2Splunk has removed the Node.js runtime environment, which it deprecated in version 10, from Splunk Enterprise as of version 10.2. This means that apps that require Node.js will no longer run. If you use or make an app that runs Node.js, then the app must include its own build of the Node.js runtime on Splunk 10.2 and higher.
The Splunk Fishbucket database back end has been replaced
Applicable components: Splunk Enterprise
Applicable OSes: AllVersion introduced: 10.2
In Splunk Enterprise 10.2, a database back end for the Fishbucket, a repository used to store file-monitoring checkpoints, was replaced with a more reliable back end.
If you are upgrading from earlier Splunk Enterprise versions, you do not need to take any action. No explicit or implicit migration is required. After the upgrade, Splunk Enterprise will continue to read existing file checkpoints from the legacy Fishbucket database. Going forward, it will write new checkpoints to and read new checkpoints from the new repository.
This information is provided because downgrading from Splunk Enterprise 10.2 to an earlier version is not officially supported. Customers who choose to downgrade may lose checkpoints that were created after the upgrade. As a result, file-monitoring state might revert to the checkpoint position that existed prior to the upgrade, which can lead to partial re-ingestion of files and potential event duplication.
KV Store requires computers that have CPUs with AVX, SSE4.2, and AES-NI
Applicable components: Splunk Enterprise
Applicable OSes: all Version introduced: 9.4, 10.0Beginning with version 9.4 of Splunk Enterprise, any computer that runs the software must have a CPU that has support for the following extensions to the x86 instruction set architecture:
- Advanced Vector Extensions (AVX)
- Streaming SIMD Extensions 4.2 (SSE4.2)
- Advanced Encryption Standard: New Instructions (AES-NI).
Typically, these extensions have support on Intel CPUs that belong to the Sandy Bridge and later microarchitecture families. There is additional support for the AMD Bulldozer 15h GEN3 family of processor chips. In both cases, there is support only for the x86-64 instruction sets.
Computers that do not use CPU processors that support AVX, SSE4.2, and AES-NI are unable to run Splunk Enterprise, and an attempt to upgrade the software on such computers will fail. This is because the latest version of the database engine that KV Store uses does not have support for CPUs that do not have support for AVX, SSE4.2, and AES-NI.
You must upgrade or replace computers that do not meet the standard before you attempt an upgrade. See Upgrade the KV store server version in the Admin Manual to learn about these new requirements for KV Store and plan the upgrade.
READ THIS FIRST: Should you deploy field filters in your organization?
Applicable components: Splunk Enterprise
Applicable OSes: all Version introduced: 9.3Field filters are a powerful tool that can help many organizations protect their sensitive fields from prying eyes, but field filters might not be a good fit for every deployment.
If your organization uses downstream configurations, such as accelerated data models, Splunk Enterprise Security (ES) detections using those data models, or user-level search-time field extractions, ensure you sufficiently plan for your field filter use cases on those configurations before deploying field filters in your environment. See READ THIS: Downstream impact of field filters.
If your organization runs Splunk Enterprise Security or if your users rely heavily on commands that field filters restricts by default (mpreview and mstats), do not use field filters in production until you have thoroughly planned how you will work around these restricted commands. See READ THIS: Restricted commands do not work in searches on indexes that have field filters.
Splunk Enterprise 9.1 fixes a critical vulnerability in deployment server but might introduce problems for older deployment clients
Applicable components: Splunk Enterprise
Applicable OSes: all Version introduced: 9.0Splunk introduced a fix for a vulnerability in deployment server in version 9.0 of Splunk Enterprise, and this fix is also available in version 9.1. If you run a deployment server, upgrade that server to version 9.1 of Splunk Enterprise as soon as possible. Before the upgrade, carefully review your deployment server setup and the current versions of the deployment clients in your Splunk Enterprise network. Depending on the setup of your deployment server and whether that component shares a computer with other Splunk Enterprise components, you might need to do the following to ensure your deployment server and clients communicate without problems:
- Isolate deployment server from other components on a machine. Isolating your deployment server means you only have to upgrade that component. The sole exception for isolation is if you run a deployment server and a license manager on the same machine.
- Confirm that all deployment clients in your network run version 7.0.0 or higher of Splunk Enterprise or the universal forwarder. You don't have to upgrade deployment clients to version 9.0.0, but they must be at version 7.0.0 or higher to communicate with version 9.0.0 deployment servers.
See the following topics for additional information:
- SVD-2022-0608 for more about the vulnerability
- Client version compatibility in the Updating Splunk Enterprise Instances Manual for more about which versions of deployment client that the version 9.0.0 deployment server supports
Follow specific instructions to upgrade clusters
Applicable components: Splunk Enterprise
Applicable OSes: all Version introduced: 7.3To upgrade indexer or search head clusters, follow the upgrade procedure for the type of deployment you have.
- If your deployment has indexer clusters, follow the index cluster upgrade instructions.
- If your deployment has search head clusters, follow the search head cluster upgrade instructions.
Back up App Key Value Store prior to starting an upgrade
Applicable components: Splunk Enterprise
Applicable OSes: all Version introduced: 7.3Back up the app key value store (KV store) before any maintenance like an upgrade.
Confirm that you have accounted for this downtime in your upgrade planning. See Back up and restore KV store for more information.
Occurrences that appear to be problems but are not
You might see things happen during or immediately after an upgrade that appear to indicate that the upgrade is not working. In nearly all cases, the occurrences that happen here can be expected.
If the following things occur during the upgrade, let the upgrade continue and do not interrupt it. If they occur immediately afterward, then perform benchmark tests on the deployment and compare to any benchmarks that you set up as part of the first phase of upgrading. Consider involving Splunk Support only if those benchmarks differ by a significant margin.
- On indexers, memory and CPU usage increases due to the following:
- New data ingestion pipelines
- Permissions on the Splunk Enterprise introspection directory might change. Confirm that the user that runs Splunk Enterprise has write permission to the
$SPLUNK_HOME/var/log/introspectiondirectory. - Deployment servers might push updates to all deployment clients due to app bundle hash recalculations.
The Splunk daemon and its associated components can now use version 3.13 of the Python interpreter, version 3.9 is still available
Applicable components: Splunk Enterprise
Applicable OSes: all Version introduced: 10.2 It's now possible to use version 3.13 of the Python interpreter for operations with the Splunk daemon. While Python version 3.9 remains the default, you can opt in to using version 3.13 for extensions like custom search commands, custom REST endpoints, scripted and modular inputs, external lookups and more. This change begins a transition toward a model where there are two versions of Python available: The long term support (LTS) version and a newer version that will ultimately become the default in a future release.Considerations for changed or removed features
The following major features have been changed or removed from this version. If you use features that have been removed, and have not yet migrated off them, consider delaying your upgrade until you have.
Splunk has removed Analytics Workspace
Applicable components: Splunk Enterprise and Universal Forwarder
Applicable OSes: all Version introduced: 10.6 Splunk removed Analytics Workspace. You can no longer use it to visualize metrics. Instead, use SPL to create metrics searches. If you open a classic dashboard that contains an Analytics Workspace panel, the Splunk platform opens that panel in the Search app. See Analytics Workspace removal in Splunk platform 10.6 on Splunk Lantern for additional information.Considerations for new features
Splunk has introduced the following new features in this version of Splunk Enterprise. You might need to perform some configuration after an upgrade to enable and take advantage of these features.
Macros now replicate by default to search peers
Applicable components: Splunk Enterprise
Applicable OSes: all Version introduced: 9.1Macros used in apps are now replicated by default to search peers as part of the knowledge bundle in Splunk deployments. As a result of this change, searches that previously failed now run successfully, which could affect downstream performance.
If you don't want to replicate macros for your apps, you can suppress replication by setting replicate.macros = false in the [replicationSettings:refineConf] stanza in the distsearch.conf file. Be aware that disabling distribution of macros might negatively impact your search results.
Learn about known upgrade issues
To learn about any additional upgrade issues for Splunk Enterprise, see the Known Issues - Upgrade Issues page in the Release Notes.