Version-Specific Upgrades
Warning
The upgrade script must be executed from within the install directory. Running ./install.sh -u from any other location will result in a failed upgrade.
cd install
./install.sh -u
Tip
If the cluster has been intentionally stopped before the upgrade, you can bypass the index compatibility check by passing the --skip-check flag:
./install.sh -u --skip-check
Use this only when you have already verified that all cluster indices are compatible with the target version.
Upgrade to Version 8.1.0
These steps cover an upgrade from 8.0.x. If you upgrade from 7.x directly to 8.1.0, follow Upgrade to Version 8.0.0 first, then complete the post-upgrade steps below as well.
Breaking changes in 8.1.0
Microsoft Teams alerter removed: The alert engine in 8.1.0 no longer ships the
ms_teamsalert type. After the upgrade the alert engine skips rules that use it, logsCould not load rule ... Error initiating alert ['ms_teams']in/var/log/alert/alert.log, and keeps running the other rules. Before you upgrade, list the affected rules and move them to another notification method, for example a webhook:
curl -u $USER:$PASSWORD "127.0.0.1:9200/.alertrules/_search?q=alertrule_any:*ms_teams*&_source=alertrulename&pretty"
Running the 8.1.0 upgrade
cd install
./install.sh -u
At the end of the run the installer prints the post-upgrade steps below. It performs some of them on its own and reports which ones failed.
Steps after upgrading to 8.1.0
SIEM Engine inventory and vulnerability detection. On every node that runs the SIEM Engine manager (
wazuh-manager), store theprobeuser credentials in the SIEM Engine keystore:/usr/share/logserver/utils/logserver-password-util.sh update_services -u probe
Confirm both prompts with
y. The command also restartswazuh-manager,logserver-probe, andlogserver-gui.Warning
In 8.1.0 the command prints
User [probe] OKbut does not store the credentials in the SIEM Engine keystore, and/var/ossec/logs/ossec.logshowsNo username and password found in the keystore. Store them by hand and restart the manager:/var/ossec/bin/wazuh-keystore -f indexer -k username -v probe /usr/share/logserver/utils/logserver-password-util.sh get_password -u probe -n | /var/ossec/bin/wazuh-keystore -f indexer -k password systemctl restart wazuh-manager
ossec.logthen showsIndexerConnector initialized successfully.Then check that the
<indexer>section in/var/ossec/etc/ossec.confis enabled and that its<host>points at the data node. The installer does not overwrite yourossec.conf. It places the 8.1.0 default next to it as/var/ossec/etc/ossec.conf.new, which you can use as a reference:<indexer> <enabled>yes</enabled> <hosts> <host>http://127.0.0.1:9200</host> </hosts> </indexer>
If the data node serves HTTPS, use an
https://address and configure the<ssl>block with your CA certificate.GeoIP and threat list scripts. The installer updates
/etc/logserver-probe/geoipdb/bin/maxmind_geoip_db.shand/etc/logserver-probe/lists/bin/misp_threat_lists.shwith the repository credentials stored in your license. If it reports Failed to fetch repo credentials from a license, update them by hand, from theinstalldirectory:[[ -f /etc/logserver-probe/geoipdb/bin/maxmind_geoip_db.sh.rpmnew ]] && mv -vf /etc/logserver-probe/geoipdb/bin/maxmind_geoip_db.sh.rpmnew /etc/logserver-probe/geoipdb/bin/maxmind_geoip_db.sh [[ -f siem/logstash/logstash/lists/bin/misp_threat_lists.sh ]] && cp -vf siem/logstash/logstash/lists/bin/misp_threat_lists.sh /etc/logserver-probe/lists/bin/misp_threat_lists.sh [[ -f logstash/logstash/lists/bin/misp_threat_lists.sh ]] && cp -vf logstash/logstash/lists/bin/misp_threat_lists.sh /etc/logserver-probe/lists/bin/misp_threat_lists.sh
Then set
GEOIP_USERandGEOIP_PASSinmaxmind_geoip_db.sh, andIOC_USERandIOC_PASSinmisp_threat_lists.sh(SIEM only), to your repository credentials.Probe user in the Network Probe keystore. On each Network Probe node, check that the
logserver-probekeystore holds theprobeuser:cd /usr/share/logserver-probe && sudo -u logserver-probe /usr/share/logserver-probe/bin/logstash-keystore --path.settings /etc/logserver-probe/ list | grep 'probe_'
The output must contain
probe_userandprobe_pass. If they are missing, add them. On a node without a local data node, point--els-urlat the data node; on a node that runs one, omit the option:/usr/share/logserver/utils/logserver-password-util.sh update_services -u probe --els-url http://<data-node>:9200
The installer runs this check and the fix on its own when it upgrades the Network Probe. On a node that also runs the client node, it does so only if you let it restart the services at the end of the upgrade.
Verifying the 8.1.0 upgrade
systemctl status logserver logserver-gui logserver-probe intelligence intelligence-scheduler alert license-service skimmer e-doc --no-pager
On SIEM nodes, also check systemctl status wazuh-manager --no-pager.
Upgrade to Version 8.0.0
Warning
Upgrading to 8.0.0 requires a full cluster restart. Rolling upgrades are not supported for this version. An upgraded node will not join an existing 7.x cluster.
Pre-upgrade steps
The Data Node update process will shut down the database service (logserver.service). Execute the following steps before running the upgrade:
Stop the collectors (Network Probe and others):
systemctl stop logserver-probe
Disable shard allocation:
curl -u $USER:$PASSWORD -X PUT "127.0.0.1:9200/_cluster/settings" \
-H "Content-Type: application/json" -d '{
"persistent": {
"cluster.routing.allocation.enable": "none"
}
}'
Perform a flush:
curl -u $USER:$PASSWORD -X POST "127.0.0.1:9200/_flush?pretty"
Run the upgrade:
./install.sh -u
Multi-node upgrade order
Warning
install.sh -u connects to the data node at http://127.0.0.1:9200 (hardcoded default; the URL prompt is skipped in upgrade mode). If network.host in logserver.yml is set to a specific IP without including 127.0.0.1 or _local_, the installer cannot reach OpenSearch and fails with Connection refused.
Before upgrading each node, verify that network.host includes the loopback address:
# /etc/logserver/logserver.yml
network.host: ["10.x.x.x", "127.0.0.1"]
Restart logserver.service on that node if you change this setting.
For multi-node deployments, run the upgrade in this order:
Start with the client node (the node that serves the GUI and coordinates queries).
When
install.shasks whether to restart services, answer No. Services on each upgraded host stay stopped until every node has finished the upgrade.Upgrade the remaining data nodes one by one using the same procedure.
Once every node has completed
install.sh -u, start the services manually across the cluster -logserverfirst on each data node, then the remaining services.After the data nodes are running and the cluster reports at least
yellowstatus, finalize the built-in user initialization on the client node:
curl -u $USER:$PASSWORD -X POST "127.0.0.1:9200/_logserver/init"
Warning
This manual step is required when upgrading from 7.9.0 or older to 8.x. On 8.x the built-in users (admin and others) are created through _logserver/init. The installer runs this initialization automatically only when it restarts logserver.service itself, which happens during a data-node upgrade if you answer Yes to the “Some system services require to be restarted” prompt. In the multi-node procedure above you answer No to that prompt and restart the services by hand, so the automatic initialization is skipped and the cluster stays uninitialized until you run _logserver/init yourself.
To check whether a node still needs initialization, query its health endpoint - an uninitialized node responds with Node uninitialized. To finalize init process please run ...:
curl -X GET "127.0.0.1:9200/_logserver/health"
Warning
The data-node RPM stops logserver.service on the host being upgraded, so the cluster runs degraded from the first node onwards. Do not let the installer restart services mid-upgrade - restart them manually only after every node has been upgraded.
Index compatibility check
The upgrade requires reindexing for indices created in versions older than Energy Logserver 7.4.0. The installation process (./install.sh -u) performs a compatibility check automatically and outputs a list of incompatible indices. These indices must be either reindexed or deleted before the upgrade can proceed.
To check index compatibility manually before downloading the installer package:
ELS_URL="http://127.0.0.1:9200"
ELS_AUTH='user:pass'
indices_metadata="$(curl --fail -XGET --insecure -u "${ELS_AUTH}" \
"${ELS_URL}/_cluster/state/metadata?filter_path=metadata.indices.**.index.version.created&pretty")"
mapfile -t indices_to_upgrade < <(echo "${indices_metadata}" | tr '\n' ' ' \
| sed -e 's/ //g' \
-e 's/,"\([^ "]\+\)":{"settings":{"index":{"version":{"created":"\([0-9]\+\)"}\+/ \1 \2/g' \
| grep -o '\S\+ [0-9]\+' \
| awk '$2 < 136217827 { print $1 }' \
| sort)
printf "%s\n" "${indices_to_upgrade[@]}"
If any indices are listed, they must be reindexed or removed before upgrading.
Breaking and major changes
JVM options: The file
jvm.optionsis overwritten by the upgrade. User-defined JVM settings must be placed in/etc/logserver/jvm.options.d/. Specifically:Heap size settings (
-Xms,-Xmx) are now in/etc/logserver/jvm.options.d/heap-size.optionsJVM temporary directory (
-Djava.io.tmpdir) is now in/etc/logserver/jvm.options.d/tmp-dir.options
If the Data Node had additional settings in
jvm.options, move them from/etc/logserver/jvm.options.rpmsaveto/etc/logserver/jvm.options.d/.Warning
-Djava.io.tmpdircannot be set to a path inside/etc/,/usr/, or/boot/.Java update: OpenJDK 21 is now required (previously OpenJDK 17).
Service names change: the services run as
logserver,logserver-gui, andlogserver-probe. The previous names remain systemd aliases, sosystemctlstill accepts them, butjournalctl -urequires the new names.License: The existing license file is reused. No replacement is required to complete the upgrade. Licenses issued for any release from 7.4.0 onwards remain valid on 8.0. A new license is only needed if you want to enable add-on features introduced in 8.0 (for example,
AI Assistant); in that case, finish the upgrade first and upload the new license from the GUI (Config → License → Upload new license).Alert Discover link field renamed: The field that injects the Discover link into an alert notification was renamed from
kibana_discovery_urltodiscovery_url(changed in 7.9.0). Rule definitions that still referencekibana_discovery_urlresolve to an empty value, so the affected alerts arrive without the link. This applies only to rules where the field was placed manually in the Rule Definition editor; alerts that use the Generate Discover URL toggle in the form are not affected. To fix an affected rule, edit the alert and rename the field. For many rules at once, replace the field name directly in the.rulesindex documents.
Post-upgrade steps
Once services on all nodes are running, re-enable shard allocation (it was set to none in the pre-upgrade steps):
curl -u $USER:$PASSWORD -X PUT "127.0.0.1:9200/_cluster/settings" \
-H "Content-Type: application/json" -d '{
"persistent": {
"cluster.routing.allocation.enable": null
}
}'
Setting the value to null restores the default (all). You can also set it explicitly to "all".
Post-upgrade verification
systemctl status logserver logserver-gui logserver-probe intelligence intelligence-scheduler alert license-service skimmer e-doc --no-pager
Upgrade from Version 7.9.0
Standard upgrade path with no special migration steps.
./install.sh -u
Post-upgrade verification:
Verify all services are running:
systemctl status logserver logserver-gui logserver-probe intelligence intelligence-scheduler alert license-service skimmer e-doc --no-pager
Test new features accessibility
Check log processing continuity
Upgrade from Version 7.8.0
Preferred Upgrade Steps for 7.8.0
Run upgrade script:
./install.sh -u
Required Post Upgrade from Version 7.8.0
Breaking and major changes
Keystore migration: The default password store has been renamed from
passstoretologserver.keystore. Run the password utility to migrate:
/usr/share/logserver/utils/logserver-password-util.sh update_services --yes --no-restart --quiet
Java update: OpenJDK 17 is now required. The upgrade script sets the correct Java version automatically. Verify after upgrade:
java -version
Backup scope expanded: The
configuration-backup.shscript now includes additional configuration files forlicense-service,intelligence, andlogserver-store. Run a post-upgrade backup to capture the full scope:
bash /usr/share/logserver/utils/configuration-backup.sh
Post-upgrade verification:
systemctl status logserver logserver-gui logserver-probe intelligence intelligence-scheduler alert license-service skimmer e-doc --no-pager
Upgrade from Version 7.7.0
Standard upgrade path with minimal changes.
./install.sh -u
Post-upgrade verification:
Test new features accessibility
Verify all services functionality
Check log processing continuity
Upgrade from Version 7.6.0
Preferred Upgrade Steps for 7.6.0
Run upgrade script:
./install.sh -u
Required Post Upgrade from Version 7.6.0
Breaking and major changes
Archive: Changed the default archives location to
/usr/share/logserver-gui/data/archive/archives/- please adjust external storage resource to this path [if used]. To customize thearchive.archivefolderpathdirective edit the/etc/logserver-gui/logserver-gui.ymlfile and restart the logserver-gui service.
sed -i 's|archive.archivefolderpath:.*|archive.archivefolderpath: "/usr/share/logserver-gui/data/archive/archives/"|' /etc/logserver-gui/logserver-gui.yml
systemctl restart logserver-gui
Network-Probe: Move required directives from
/opt/license-service/license-service.confto/opt/license-service/license-service.conf.rpmnewand replacelicense-service.confthen restart the license-service.
Upgrade from Version 7.5.0
Preferred Upgrade Steps for 7.5.0
Run upgrade script:
./install.sh -u
Required Post Upgrade from Version 7.5.0
Breaking and major changes
User “logserver” will no longer be able to log into GUI. Use “admin” user instead. The update process will print the generated password for this new user. In case you have missed it you can run the following command on your main client node to recover the password:
/usr/share/logserver/utils/logserver-password-util.sh get_password -u admin -q
Upgrade from Version 7.4.2 / 7.4.3
Preferred Upgrade Steps for 7.4.2 / 7.4.3
Run upgrade script:
./install.sh -u
Required Post Upgrade from Version 7.4.2 / 7.4.3
Breaking and major changes
Network-Probe replaces Logserver-Probe: follow the steps below.
LOGSERVER-PROBE:
Backup
/etc/logserver-probe
cp -r /etc/logserver-probe /backup/logserver-probe-7.4-backup/
Uninstall old version:
Warning
This command permanently removes Network Probe configuration and data. Ensure you have a backup before proceeding.
yum versionlock delete logserver-probe-oss-7.17.11-1
yum remove logserver-probe-oss
rm -rf /etc/logserver-probe /var/lib/logserver-probe /usr/share/logserver-probe
Install the current Input Layer from scratch using
sudo ./install.sh -i- Network-Probe SectionRestore from backup custom pipelines to
/etc/logserver-probe/conf.d/
cp /backup/logserver-probe-7.4-backup/conf.d/* /etc/logserver-probe/conf.d/
ENERGYLOGSERVER
./install.shchecks indexes compatibility before upgrading. If any problems exist, please contact product support to guide you through the upgrade process.Move required directives from
/etc/logserver/logserver.ymlto/etc/logserver/logserver.yml.rpmnewand replacelogserver.yml.
mv /etc/logserver/logserver.yml /etc/logserver/logserver.yml.backup
mv /etc/logserver/logserver.yml.rpmnew /etc/logserver/logserver.yml
LOGSERVER-GUI
Move required directives from
/etc/logserver-gui/logserver-gui.ymlto/etc/logserver-gui/logserver-gui.yml.rpmnewand replacelogserver-gui.yml.
mv /etc/logserver-gui/logserver-gui.yml /etc/logserver-gui/logserver-gui.yml.backup
mv /etc/logserver-gui/logserver-gui.yml.rpmnew /etc/logserver-gui/logserver-gui.yml
Clear browser cache on client side.
LICENSE-SERVICE
If required, configure
logserver_connectionin/opt/license-service/license-service.conf.Old configuration should be in
/opt/license-service/license-service.conf.rpmsave. Do not replacelicense-service.confwithlicense-service.conf.rpmsave
EMPOWERED-AI (7.4.3 only)
Backup
.intelligence_models,.intelligence_rule_configurationindices - if neededStop services:
systemctl stop empowered-ai
Delete old indices:
curl -XDELETE '127.0.0.1:9200/.intelligence_rule_configuration,.intelligence_models,.intelligence_results' -u $USER:$PASSWORD
Start services:
systemctl start empowered-ai
Upgrade from Version 7.4.1
Preferred Upgrade Steps for 7.4.1
Run upgrade script:
./install.sh -u
No additional post-upgrade steps are required for this version.
Upgrade from Version 7.4.0
Preferred Upgrade Steps for 7.4.0
Run upgrade script:
./install.sh -u
No additional post-upgrade steps are required for this version.
Upgrade from Version 7.3.0
Preferred Upgrade Steps for 7.3.0
Run upgrade script:
./install.sh -u
Required Post Upgrade from Version 7.3.0
ENERGYLOGSERVER
./install.shchecks indexes compatibility before upgrading. If any problems exist, please contact product support to guide you through the upgrade process.Move required directives from
/etc/logserver/logserver.ymlto/etc/logserver/logserver.yml.rpmnewand replacelogserver.yml.
LOGSERVER-GUI
Move required directives from
/etc/logserver-gui/logserver-gui.ymlto/etc/logserver-gui/logserver-gui.yml.rpmnewand replacelogserver-gui.yml.Clear browser cache on client side.
LOGSERVER-PROBE
Backup
/etc/logserver-probeUninstall old version:
yum versionlock delete logserver-probe-oss-7.17.11-1
yum remove logserver-probe-oss
rm -rf /etc/logserver-probe /var/lib/logserver-probe /usr/share/logserver-probe
Install the current Input Layer from scratch using
sudo ./install.sh -i- Network-Probe Section.Restore from backup custom pipelines to
/etc/logserver-probe/conf.d/
LICENSE-SERVICE
If required, configure
logserver_connectionin/opt/license-service/license-service.conf.Old configuration should be in
/opt/license-service/license-service.conf.rpmsave. Do not replacelicense-service.confwithlicense-service.conf.rpmsave
EMPOWERED-AI Migration (7.3.0 only):
curl -X POST "localhost:9200/_snapshot/backup_repo/intelligence_backup" -H 'Content-Type: application/json' -u $USER:$PASSWORD -d'
{
"indices": ".intelligence_models,.intelligence_rule_configuration"
}'
systemctl stop empowered-ai
yum remove empowered-ai
./install.sh -u