# Question about migrating to 4.3.0

**URL:** <https://community.graylog.org/t/question-about-migrating-to-4-3-0/24088>\
**Category:** Graylog Central (peer support)\
**Created:** [May 30, 2022, 11:40pm UTC](https://community.graylog.org/t/question-about-migrating-to-4-3-0/24088 "2022-05-30T23:40:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![junior466](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/junior466/32/2939_2.png) [@junior466](https://community.graylog.org/u/junior466)\
**Post date:** [May 30, 2022, 11:40pm UTC](https://community.graylog.org/t/question-about-migrating-to-4-3-0/24088/1 "2022-05-30T23:40:21Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.  
**Don’t forget to select tags to help index your topic!**

**1. Describe your incident:**  
Looking to migrate to OpenSearch as recommended

**2. Describe your environment:**

- OS Information:

Ubuntu 18.04.6 LTS

- Package Version:

Graylog 4.2.9

- Service logs, configurations, and environment variables:

**4. How can the community help?**

Greetings!

I would like to ask since I am running Graylog 4.2.9, I would like to upgrade to 4.3.0 and keep my ElasticSearch install but am a bit confused with this warning:

```
We caution you not to install or upgrade Elasticsearch to 7.11 and later! It is not supported. If you do so, it will break your instance!

```

When I run `curl -X GET "localhost:9200/?pretty"` I show that my ElasticSearch version is `7.17.2` so that means I should not upgrade?

```
    {
      "name" : "u1804graylog",
      "cluster_name" : "graylog",
      "cluster_uuid" : "xxxxxxxxxxx",
      "version" : {
        "number" : "7.17.2",
        "build_flavor" : "default",
        "build_type" : "deb",
        "build_hash" : "xxxxxxxxxxx",
        "build_date" : "2022-03-28T15:12:21.446567561Z",
        "build_snapshot" : false,
        "lucene_version" : "8.11.1",
        "minimum_wire_compatibility_version" : "6.8.0",
        "minimum_index_compatibility_version" : "6.0.0-beta1"
      },
      "tagline" : "You Know, for Search"
    }

```

Does that mean I shouldn’t upgrade to 4.3.0 since I am above the recommended `7.11`?

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [May 30, 2022, 11:55pm UTC](https://community.graylog.org/t/question-about-migrating-to-4-3-0/24088/2 "2022-05-30T23:55:18Z")

</div>

Hello,

Some bad news.

1.Graylog supports Elasticsearch-7.10.x not recommended to go beyond that version  
2.OpenSearch for Graylog only supports 1.2,1.3 which is equal to Elasticsearch 7.10.x  
3.Since your above 7.10 not sure but I don’t think its going to be good.  
4.Last, Graylog 4.3 has a PRE-FLIGHT CHECKS _"When Graylog starts up, it now performs connectivity and version checks for MongoDB and Elasticsearch/OpenSearch. "_ Thats probably why you see those errors when upgrading to 4.3.

Depending on this environment you could down grade ES **BUT** there will be data loss.

Resources

- [Graylog To Add Support for OpenSearch | Graylog](https://www.graylog.org/post/graylog-to-add-support-for-opensearch)

- [Upgrade from Elasticsearch OSS to OpenSearch - OpenSearch documentation](https://opensearch.org/docs/1.3/upgrade-to/upgrade-to/)

- [Announcing Graylog v4.3, Graylog Operations, & Graylog Security | Graylog](https://www.graylog.org/post/announcing-graylog-v4-3-graylog-operations-graylog-security)

I had this happen before, it was a mess downgrading Elasticsearch . Now I always “PIN” my repo.

---

<div class="post-metadata">

**Author:** ![junior466](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/junior466/32/2939_2.png) [@junior466](https://community.graylog.org/u/junior466)\
**Post date:** [May 31, 2022, 12:34am UTC](https://community.graylog.org/t/question-about-migrating-to-4-3-0/24088/3 "2022-05-31T00:34:01Z")

</div>

I don’t think I will chance it and simply upgrade to OpenSearch as the instructions for migrating seems straightforward enough.

Anything I should be aware of before I make the move?

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [May 31, 2022, 12:39am UTC](https://community.graylog.org/t/question-about-migrating-to-4-3-0/24088/4 "2022-05-31T00:39:46Z")

</div>

@junior466  
Yes this section of the link posted.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/ece59c13aeff7f5fc8a6d42db4b778f6ec0a0f06.png)  
Other then that, tell us how it went.

**EDIT** : Just an FYI

> [@junior466](#):
>
> simply upgrade to OpenSearch

If you install OpenSearch as instructed it will be either version 1.2 or 1.3 which equals ES 7.10. So that statement is incorrect you will be down grading not upgrading

---

<div class="post-metadata">

**Author:** ![junior466](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/junior466/32/2939_2.png) [@junior466](https://community.graylog.org/u/junior466)\
**Post date:** [June 7, 2022, 6:46pm UTC](https://community.graylog.org/t/question-about-migrating-to-4-3-0/24088/5 "2022-06-07T18:46:09Z")

</div>

> If you install OpenSearch as instructed it will be either version 1.2 or 1.3 which equals ES 7.10. So that statement is incorrect you will be down grading not upgrading

Sorry for reviving this but not sure I fully understand. What version of OpenSearch should I install/recommended?

I just tried following the migration guide today but ran across some issues as the documentation doesn’t appear to be complete. I am running Ubuntu 18.04 and not sure if I should be installing the docker, docker-compose or tar method.

Just looking for the most reliable and easiest way.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [June 7, 2022, 9:58pm UTC](https://community.graylog.org/t/question-about-migrating-to-4-3-0/24088/6 "2022-06-07T21:58:20Z")

</div>

Hello @junior466

> [@junior466](#):
>
> Sorry for reviving this but not sure I fully understand. What version of OpenSearch should I install/recommended?

I just posted this above, “Three times a charm” 😉 I have installed 1.3, this would be up to you

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/a/a55aca3dec0944817390792868f0b6c15b15f255.png)

As for this…

> [@junior466](#):
>
> I am running Ubuntu 18.04 and not sure if I should be installing the docker, docker-compose or tar method.

I agree the documentation is behind a little. You can use YUM/RPM now to install OpenSearch but not with APT yet.

Please take a look at this link.

> **[Next OpenSearch Distribution Support](https://forum.opensearch.org/t/next-opensearch-distribution-support/9699)**
>
> Hello all, With RPM distribution out in 1.3.2 version, the OpenSearch build team is moving forward to start working on the next distribution support. Based on the interests received, both Windows and Debian distributions are the next top...

To be honest, I would wait to upgrade, one reason is that you have Elasticsearch version that’s is beyond what is supported by Graylog and/or OpenSearch

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [June 21, 2022, 9:59pm UTC](https://community.graylog.org/t/question-about-migrating-to-4-3-0/24088/7 "2022-06-21T21:59:21Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
