Upgrade path for Splunk SOAR (On-premises) unprivileged installations

Unprivileged deployments of Splunk Phantom or Splunk SOAR (On-premises) have a more streamlined upgrade path than privileged deployments.

Upgrade paths:

  • Unprivileged Splunk Phantom deployments running a release earlier than release 4.10.7 must be upgraded incrementally from release to release, until Splunk Phantom release 4.10.7.
  • Unprivileged Splunk Phantom deployments running release 4.10.7 can be upgraded directly to Splunk SOAR (On-premises) release 6.2.1, then can upgrade to release 6.3.0.
  • Unprivileged Splunk SOAR (On-premises) running a release earlier than release 6.2.1 can be upgraded to Splunk SOAR (On-premises) release 6.2.1, and then to release 6.3.0.
  • Deployments running on the CentOS 7 operating system must migrate to a supported operating system before they can upgrade beyond release 6.3.0.
  • Deployments running on Amazon Linux 2 must migrate to a supported operating system before they can upgrade beyond release 6.4.0. See Migrate a Splunk SOAR (On-premises) install from Amazon Linux 2 to Amazon Linux 2023.
CAUTION: All deployments must upgrade to Splunk SOAR (On-premises) 6.2.1 before upgrading to higher releases in order to upgrade the PostgreSQL database. PostgreSQL databases local to the SOAR deployment are updated to PostgreSQL 15.x during the upgrade process. The PostgreSQL database for all clustered deployments, or deployments using an external database must be upgraded manually.
If your Splunk SOAR (On-premises) deployment is running on the CentOS operating system, you must migrate the deployment to a supported operating system before you can upgrade beyond release 6.3.0.
A list of important or breaking changes and the versions where those changes occur is in Splunk SOAR (On-premises) upgrade overview and prerequisites. Review that list before upgrading.

Upgrade path table

Look on the following table to find your currently installed Splunk Phantom or Splunk SOAR (On-premises) release to see your complete upgrade path.

Starting version Path to current version Details
4.6.19142
  1. Upgrade to 4.8.24304
  2. Upgrade to 4.9.39220
  3. Upgrade to 4.10.7
  4. Upgrade to 6.2.1
  5. (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x
  6. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8.
  7. Upgrade to 8.5.0
  1. Upgrade to 4.8.24304
  2. Upgrade to 4.9.39220
  3. Upgrade to 4.10.7
  4. Upgrade to 6.2.1
  5. (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
    1. See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
  6. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8. See Migrate a Splunk SOAR (On-premises) install from RHEL 7 or CentOS 7 to RHEL 8
  7. Upgrade to 8.5.0
4.8.24304
  1. Upgrade to 4.8.24304
  2. Upgrade to 4.9.39220
  3. Upgrade to 4.10.7
  4. Upgrade to 6.2.1
  5. (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x
  6. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8.
  7. Upgrade to 8.5.0
  1. Upgrade to 4.9.39220
  2. Upgrade to 4.10.7
  3. Upgrade to 6.2.1
  4. (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
    1. See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
  5. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8. See Migrate a Splunk SOAR (On-premises) install from RHEL 7 or CentOS 7 to RHEL 8
  6. Upgrade to 8.5.0
4.9.39220
  1. Upgrade to 4.10.7
  2. Upgrade to 6.2.1
  3. (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x
  4. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8.
  5. Upgrade to 8.5.0
  1. Upgrade to 4.10.7
  2. Upgrade to 6.2.1
  3. (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
    1. See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
  4. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8. See Migrate a Splunk SOAR (On-premises) install from RHEL 7 or CentOS 7 to RHEL 8
  5. Upgrade to 8.5.0
4.10.0 - 4.10.6
  1. Upgrade to 4.10.7
  2. Upgrade to 6.2.1
  3. (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x
  4. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8.
  5. Upgrade to 8.5.0
  1. Upgrade to 4.10.7
  2. Upgrade to 6.2.1
  3. (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
    1. See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
  4. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8. See Migrate a Splunk SOAR (On-premises) install from RHEL 7 or CentOS 7 to RHEL 8
  5. Upgrade to 8.5.0
4.10.7
  1. Upgrade to 6.2.1
  2. (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x
  3. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8.
  4. Upgrade to 8.5.0
  1. Upgrade to 6.2.1
  2. (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
    1. See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
  3. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8. See Migrate a Splunk SOAR (On-premises) install from RHEL 7 or CentOS 7 to RHEL 8
  4. Upgrade to 8.5.0
5.0.1 - 6.1.0
  1. Upgrade to 6.2.1
  2. (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x
  3. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8.
  4. (Conditional) If you are using Amazon Linux 2:
    1. Upgrade to Splunk SOAR 6.4.0
    2. Upgrade your OS to Amazon Linux 2023 or another supported operating system.
  5. Upgrade to 8.5.0
  1. Upgrade to 6.2.1
  2. (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
    1. See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
  3. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8. See Migrate a Splunk SOAR (On-premises) install from RHEL 7 or CentOS 7 to RHEL 8
  4. (Conditional) If you are using Amazon Linux 2:
    1. Upgrade to Splunk SOAR 6.4.0.

    2. Upgrade your OS to Amazon Linux 2023.

      See Upgrade your Splunk SOAR (On-premises) deployment on Amazon Linux 2 to a new Amazon Linux 2023 host by using backup and restore
  5. Upgrade to 8.5.0
  • 6.1.1

  • 6.2.0

  • 6.2.1

  1. (Conditional) If you have a clustered deployment, or an external PostgreSQL 11.x database, upgrade your external PostgreSQL 11.x database to PostgreSQL 15.x
  2. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8.
  3. (Conditional) If you are using Amazon Linux 2:
    1. Upgrade to Splunk SOAR 6.4.0
    2. Upgrade your OS to Amazon Linux 2023 or another supported operating system.
  4. Upgrade to 8.5.0
  1. (Conditional) Clustered deployments or deployments with an external PostgreSQL 11.x database, upgrade PostgreSQL to 15.x
    1. See Upgrading a PostgreSQL Cluster on PostgreSQL.org.
  2. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8. See Migrate a Splunk SOAR (On-premises) install from RHEL 7 or CentOS 7 to RHEL 8
  3. (Conditional) If you are using Amazon Linux 2:
    1. Upgrade to Splunk SOAR 6.4.0.

    2. Upgrade your OS to Amazon Linux 2023.

      See Upgrade your Splunk SOAR (On-premises) deployment on Amazon Linux 2 to a new Amazon Linux 2023 host by using backup and restore
  4. Upgrade to 8.5.0
  • 6.2.2
  • 6.3.0

  1. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8.
  2. (Conditional) If you are using Amazon Linux 2:
    1. Upgrade to Splunk SOAR 6.4.0
    2. Upgrade your OS to Amazon Linux 2023 or another supported operating system.
  3. Upgrade to 8.5.0
  1. (Conditional) If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8. See Migrate a Splunk SOAR (On-premises) install from RHEL 7 or CentOS 7 to RHEL 8
  2. (Conditional) If you are using Amazon Linux 2:
    1. Upgrade to Splunk SOAR 6.4.0.

    2. Upgrade your OS to Amazon Linux 2023.

      See Upgrade your Splunk SOAR (On-premises) deployment on Amazon Linux 2 to a new Amazon Linux 2023 host by using backup and restore
  3. Upgrade to 8.5.0
  • 6.3.1
  • 6.4.0

  1. (Conditional) If you are using Amazon Linux 2:
    1. Upgrade to Splunk SOAR 6.4.0
    2. Upgrade your OS to Amazon Linux 2023 or another supported operating system.
  2. Upgrade to 8.5.0
  1. (Conditional) If you are using Amazon Linux 2:
    1. Upgrade to Splunk SOAR 6.4.0.

    2. Upgrade your OS to Amazon Linux 2023.

      See Upgrade your Splunk SOAR (On-premises) deployment on Amazon Linux 2 to a new Amazon Linux 2023 host by using backup and restore
  2. Upgrade to 8.5.0

6.4.1.361 and higher

Including:

  • 7.0.0.197

  • 7.1.0

  • 8.4.0

Upgrade to 8.5.0 Upgrade to 8.5.0

Example

To upgrade from Splunk Phantom release 4.6 to Splunk SOAR (On-premises) 8.5.0, using :

  1. Upgrade your Splunk Phantom to release 4.8.24304
  2. Upgrade Splunk Phantom to release 4.9.39220
  3. Upgrade Splunk Phantom to release 4.10.7.63984
  4. Upgrade to Splunk SOAR (On-premises) release 6.2.1
  5. If you are using CentOS or Red Hat Enterprise Linux 7, upgrade to Oracle Linux 8 or Red Hat Enterprise Linux 8.
  6. (Conditional) If you are using Amazon Linux 2:
    1. Upgrade to Splunk SOAR 6.4.0
    2. Upgrade your OS to Amazon Linux 2023 or another supported operating system.
  7. Upgrade to 8.5.0