Configure a Proxy Connection for Indexer Upgrades
If your Linux Data Indexer sits behind a proxy server, you need to add the proxy address and optional username and password to the yum configuration file on the Indexer from which you are running the upgrade.
To configure proxy options in yum.conf:
-
Log on to your Indexer appliance or server as logrhythm.
-
To open the file for editing, type:
sudo vi /etc/yum.conf -
To enter INSERT mode, type i.
-
Add the following lines to the file:
proxy=<proxyURL:port>proxy_username=<username>proxy_password=<password>Press Esc.
EXAMPLE
proxy=http://my.proxyaddress.com:9999/
proxy_username=myloginID
proxy_password=mypassword
-
To exit and save yum.conf type
:wq
Configure Upgrades Without Internet Access (Dark Sites)
If your Linux Data Indexer does not have access to the Internet (for example, in a restricted environment or at a dark site), you may need to modify CentOS-Base.repo so that repositories are skipped if they are unavailable.
CentOS-Base.repo contains the base, updates, extras, and centosplus repositories. By default, updates to centosplus are disabled (i.e., enabled is set to 0). For base, updates, and extras, you will need to add a line that will skip updates if the repo is unavailable.
If you are upgrading a multi-node cluster, you only need to modify CentOS-Base.repo on the node from which you will be running the upgrade.
To configure repository options in CentOS-Base.repo:
-
Log in to your Indexer appliance or server as logrhythm.
-
To open the file for editing, type:
sudo vi /etc/yum.repos.d/CentOS-Base.repo -
To enter INSERT mode, type i.
-
Within each of the three repository sections — base, updates, and extras — add the following line:
skip_if_unavailable=true -
Press Esc.
-
To exit and save CentOS-Base.repo type
:wq
Upgrade a Single-node Cluster
Before starting the Data Indexer upgrade, ensure that firewalld is running on all cluster nodes. To do this, log on to each node and run:
sudo systemctl start firewalld
-
Log on to your Indexer appliance or server as logrhythm.
-
Change to the /home/logrhythm/Soft directory where you copied the updated installation or upgrade script.
-
If you need to create a hosts file, use
vito create a file in /home/logrhythm/Soft called hosts.
If you are creating a new file, ensure that you specify the current Data Indexer hostname.
The hosts file must follow a defined pattern of {IPv4 address} {hostname} {boxtype} on each line. You must separate the address and hostname with a space. The file might look like the following for a multi-node cluster:
10.1.23.65 LRLinux1 hot
10.1.23.67 LRLinux2 warm
10.1.23.91 LRLinux3 warm
Do not use fully qualified domain names for Indexer hosts. For example, use only LRLinux1 instead of LRLinux1.myorg.com.
The following command sequence illustrates how to create and modify a file with vi:
-
-
To create the hosts file and open for editing, type vi hosts.
-
To enter INSERT mode, type i.
-
Enter the IPv4 address, hostname to use for the Indexer, and box type, separated by a space.
-
Press Esc.
-
To exit and save your hosts file, type
:wq
-
-
Download the DataIndexerLinux.zip file from the Documentation & Downloads section of the LogRhythm Community, extract the contents of the zip and place all files in /home/logrhythm/Soft.
-
Run the installer with the hosts file argument:
sudo sh LRDataIndexer-<version>.x86_64.run --hosts <absolute path to .hosts file> --plan /home/logrhythm/Soft/plan.yml
Press Tab after starting to type out the installer name, and the filename autocompletes for you.
-
The script installs or upgrades the Data Indexer.
When the installation or upgrade is complete, a confirmation message appears.
This process may take up to 30 minutes.
-
Check the status of services by typing sudo systemctl at the prompt, and then look for failed services.
If the installation or upgrade fails with the error “failed to connect to the firewalld daemon,” ensure that firewalld is running on all cluster nodes and start this procedure again. To do this, log in to each node and run the following command: sudo systemctl start firewalld
Once the cluster restarts, there will be a short period of downtime as the DX update finalizes.
Validate the Linux Data Indexer Upgrade
To validate a successful upgrade of the Linux Indexer, check the following logs in /var/log/persistent:
-
ansible.log echoes console output from the upgrade, and should end with details about the number of components that upgraded successfully, as well as any issues (unreachable or failed)
-
logrhythm-node-install.sh.log lists all components that were installed or updated, along with current versions
-
logrhythm-cluster-install.sh.log should end with a message stating that the Indexer was successfully installed
Additionally, you can issue the following command and verify the installed version of various LogRhythm services, tools, and libraries, as well as third party tools:
sudo yum list installed | grep -i logrhythm
-
Verify the following versions of these services and third party tools:
-
elasticsearch 7.10.2
-