Version-Specific Upgrades

Warning

The upgrade script must be executed from within the install directory. Running ./install.sh -u from any other location will result in a failed upgrade.

cd install
./install.sh -u

Tip

If the cluster has been intentionally stopped before the upgrade, you can bypass the index compatibility check by passing the --skip-check flag:

./install.sh -u --skip-check

Use this only when you have already verified that all cluster indices are compatible with the target version.

Upgrade to Version 8.1.0

These steps cover an upgrade from 8.0.x. If you upgrade from 7.x directly to 8.1.0, follow Upgrade to Version 8.0.0 first, then complete the post-upgrade steps below as well.

Breaking changes in 8.1.0

  • Microsoft Teams alerter removed: The alert engine in 8.1.0 no longer ships the ms_teams alert type. After the upgrade the alert engine skips rules that use it, logs Could not load rule ... Error initiating alert ['ms_teams'] in /var/log/alert/alert.log, and keeps running the other rules. Before you upgrade, list the affected rules and move them to another notification method, for example a webhook:

curl -u $USER:$PASSWORD "127.0.0.1:9200/.alertrules/_search?q=alertrule_any:*ms_teams*&_source=alertrulename&pretty"

Running the 8.1.0 upgrade

cd install
./install.sh -u

At the end of the run the installer prints the post-upgrade steps below. It performs some of them on its own and reports which ones failed.

Steps after upgrading to 8.1.0

  1. SIEM Engine inventory and vulnerability detection. On every node that runs the SIEM Engine manager (wazuh-manager), store the probe user credentials in the SIEM Engine keystore:

    /usr/share/logserver/utils/logserver-password-util.sh update_services -u probe
    

    Confirm both prompts with y. The command also restarts wazuh-manager, logserver-probe, and logserver-gui.

    Warning

    In 8.1.0 the command prints User [probe] OK but does not store the credentials in the SIEM Engine keystore, and /var/ossec/logs/ossec.log shows No username and password found in the keystore. Store them by hand and restart the manager:

    /var/ossec/bin/wazuh-keystore -f indexer -k username -v probe
    /usr/share/logserver/utils/logserver-password-util.sh get_password -u probe -n | /var/ossec/bin/wazuh-keystore -f indexer -k password
    systemctl restart wazuh-manager
    

    ossec.log then shows IndexerConnector initialized successfully.

    Then check that the <indexer> section in /var/ossec/etc/ossec.conf is enabled and that its <host> points at the data node. The installer does not overwrite your ossec.conf. It places the 8.1.0 default next to it as /var/ossec/etc/ossec.conf.new, which you can use as a reference:

    <indexer>
      <enabled>yes</enabled>
      <hosts>
        <host>http://127.0.0.1:9200</host>
      </hosts>
    </indexer>
    

    If the data node serves HTTPS, use an https:// address and configure the <ssl> block with your CA certificate.

  2. GeoIP and threat list scripts. The installer updates /etc/logserver-probe/geoipdb/bin/maxmind_geoip_db.sh and /etc/logserver-probe/lists/bin/misp_threat_lists.sh with the repository credentials stored in your license. If it reports Failed to fetch repo credentials from a license, update them by hand, from the install directory:

    [[ -f /etc/logserver-probe/geoipdb/bin/maxmind_geoip_db.sh.rpmnew ]] && mv -vf /etc/logserver-probe/geoipdb/bin/maxmind_geoip_db.sh.rpmnew /etc/logserver-probe/geoipdb/bin/maxmind_geoip_db.sh
    [[ -f siem/logstash/logstash/lists/bin/misp_threat_lists.sh ]] && cp -vf siem/logstash/logstash/lists/bin/misp_threat_lists.sh /etc/logserver-probe/lists/bin/misp_threat_lists.sh
    [[ -f logstash/logstash/lists/bin/misp_threat_lists.sh ]] && cp -vf logstash/logstash/lists/bin/misp_threat_lists.sh /etc/logserver-probe/lists/bin/misp_threat_lists.sh
    

    Then set GEOIP_USER and GEOIP_PASS in maxmind_geoip_db.sh, and IOC_USER and IOC_PASS in misp_threat_lists.sh (SIEM only), to your repository credentials.

  3. Probe user in the Network Probe keystore. On each Network Probe node, check that the logserver-probe keystore holds the probe user:

    cd /usr/share/logserver-probe && sudo -u logserver-probe /usr/share/logserver-probe/bin/logstash-keystore --path.settings /etc/logserver-probe/ list | grep 'probe_'
    

    The output must contain probe_user and probe_pass. If they are missing, add them. On a node without a local data node, point --els-url at the data node; on a node that runs one, omit the option:

    /usr/share/logserver/utils/logserver-password-util.sh update_services -u probe --els-url http://<data-node>:9200
    

    The installer runs this check and the fix on its own when it upgrades the Network Probe. On a node that also runs the client node, it does so only if you let it restart the services at the end of the upgrade.

Verifying the 8.1.0 upgrade

systemctl status logserver logserver-gui logserver-probe intelligence intelligence-scheduler alert license-service skimmer e-doc --no-pager

On SIEM nodes, also check systemctl status wazuh-manager --no-pager.

Upgrade to Version 8.0.0

Warning

Upgrading to 8.0.0 requires a full cluster restart. Rolling upgrades are not supported for this version. An upgraded node will not join an existing 7.x cluster.

Pre-upgrade steps

The Data Node update process will shut down the database service (logserver.service). Execute the following steps before running the upgrade:

  1. Stop the collectors (Network Probe and others):

systemctl stop logserver-probe
  1. Disable shard allocation:

curl -u $USER:$PASSWORD -X PUT "127.0.0.1:9200/_cluster/settings" \
  -H "Content-Type: application/json" -d '{
  "persistent": {
    "cluster.routing.allocation.enable": "none"
  }
}'
  1. Perform a flush:

curl -u $USER:$PASSWORD -X POST "127.0.0.1:9200/_flush?pretty"
  1. Run the upgrade:

./install.sh -u

Multi-node upgrade order

Warning

install.sh -u connects to the data node at http://127.0.0.1:9200 (hardcoded default; the URL prompt is skipped in upgrade mode). If network.host in logserver.yml is set to a specific IP without including 127.0.0.1 or _local_, the installer cannot reach OpenSearch and fails with Connection refused.

Before upgrading each node, verify that network.host includes the loopback address:

# /etc/logserver/logserver.yml
network.host: ["10.x.x.x", "127.0.0.1"]

Restart logserver.service on that node if you change this setting.

For multi-node deployments, run the upgrade in this order:

  1. Start with the client node (the node that serves the GUI and coordinates queries).

  2. When install.sh asks whether to restart services, answer No. Services on each upgraded host stay stopped until every node has finished the upgrade.

  3. Upgrade the remaining data nodes one by one using the same procedure.

  4. Once every node has completed install.sh -u, start the services manually across the cluster - logserver first on each data node, then the remaining services.

  5. After the data nodes are running and the cluster reports at least yellow status, finalize the built-in user initialization on the client node:

curl -u $USER:$PASSWORD -X POST "127.0.0.1:9200/_logserver/init"

Warning

This manual step is required when upgrading from 7.9.0 or older to 8.x. On 8.x the built-in users (admin and others) are created through _logserver/init. The installer runs this initialization automatically only when it restarts logserver.service itself, which happens during a data-node upgrade if you answer Yes to the “Some system services require to be restarted” prompt. In the multi-node procedure above you answer No to that prompt and restart the services by hand, so the automatic initialization is skipped and the cluster stays uninitialized until you run _logserver/init yourself.

To check whether a node still needs initialization, query its health endpoint - an uninitialized node responds with Node uninitialized. To finalize init process please run ...:

curl -X GET "127.0.0.1:9200/_logserver/health"

Warning

The data-node RPM stops logserver.service on the host being upgraded, so the cluster runs degraded from the first node onwards. Do not let the installer restart services mid-upgrade - restart them manually only after every node has been upgraded.

Index compatibility check

The upgrade requires reindexing for indices created in versions older than Energy Logserver 7.4.0. The installation process (./install.sh -u) performs a compatibility check automatically and outputs a list of incompatible indices. These indices must be either reindexed or deleted before the upgrade can proceed.

To check index compatibility manually before downloading the installer package:

ELS_URL="http://127.0.0.1:9200"
ELS_AUTH='user:pass'

indices_metadata="$(curl --fail -XGET --insecure -u "${ELS_AUTH}" \
  "${ELS_URL}/_cluster/state/metadata?filter_path=metadata.indices.**.index.version.created&pretty")"

mapfile -t indices_to_upgrade < <(echo "${indices_metadata}" | tr '\n' ' ' \
  | sed -e 's/ //g' \
        -e 's/,"\([^ "]\+\)":{"settings":{"index":{"version":{"created":"\([0-9]\+\)"}\+/ \1 \2/g' \
  | grep -o '\S\+ [0-9]\+' \
  | awk '$2 < 136217827 { print $1 }' \
  | sort)

printf "%s\n" "${indices_to_upgrade[@]}"

If any indices are listed, they must be reindexed or removed before upgrading.

Breaking and major changes

  • JVM options: The file jvm.options is overwritten by the upgrade. User-defined JVM settings must be placed in /etc/logserver/jvm.options.d/. Specifically:

    • Heap size settings (-Xms, -Xmx) are now in /etc/logserver/jvm.options.d/heap-size.options

    • JVM temporary directory (-Djava.io.tmpdir) is now in /etc/logserver/jvm.options.d/tmp-dir.options

    If the Data Node had additional settings in jvm.options, move them from /etc/logserver/jvm.options.rpmsave to /etc/logserver/jvm.options.d/.

    Warning

    -Djava.io.tmpdir cannot be set to a path inside /etc/, /usr/, or /boot/.

  • Java update: OpenJDK 21 is now required (previously OpenJDK 17).

  • Service names change: the services run as logserver, logserver-gui, and logserver-probe. The previous names remain systemd aliases, so systemctl still accepts them, but journalctl -u requires the new names.

  • License: The existing license file is reused. No replacement is required to complete the upgrade. Licenses issued for any release from 7.4.0 onwards remain valid on 8.0. A new license is only needed if you want to enable add-on features introduced in 8.0 (for example, AI Assistant); in that case, finish the upgrade first and upload the new license from the GUI (Config → License → Upload new license).

  • Alert Discover link field renamed: The field that injects the Discover link into an alert notification was renamed from kibana_discovery_url to discovery_url (changed in 7.9.0). Rule definitions that still reference kibana_discovery_url resolve to an empty value, so the affected alerts arrive without the link. This applies only to rules where the field was placed manually in the Rule Definition editor; alerts that use the Generate Discover URL toggle in the form are not affected. To fix an affected rule, edit the alert and rename the field. For many rules at once, replace the field name directly in the .rules index documents.

Post-upgrade steps

Once services on all nodes are running, re-enable shard allocation (it was set to none in the pre-upgrade steps):

curl -u $USER:$PASSWORD -X PUT "127.0.0.1:9200/_cluster/settings" \
  -H "Content-Type: application/json" -d '{
  "persistent": {
    "cluster.routing.allocation.enable": null
  }
}'

Setting the value to null restores the default (all). You can also set it explicitly to "all".

Post-upgrade verification

systemctl status logserver logserver-gui logserver-probe intelligence intelligence-scheduler alert license-service skimmer e-doc --no-pager

Upgrade from Version 7.9.0

Standard upgrade path with no special migration steps.

./install.sh -u

Post-upgrade verification:

  • Verify all services are running:

systemctl status logserver logserver-gui logserver-probe intelligence intelligence-scheduler alert license-service skimmer e-doc --no-pager
  • Test new features accessibility

  • Check log processing continuity

Upgrade from Version 7.8.0

Preferred Upgrade Steps for 7.8.0

  1. Run upgrade script:

./install.sh -u

Required Post Upgrade from Version 7.8.0

Breaking and major changes

  • Keystore migration: The default password store has been renamed from passstore to logserver.keystore. Run the password utility to migrate:

/usr/share/logserver/utils/logserver-password-util.sh update_services --yes --no-restart --quiet
  • Java update: OpenJDK 17 is now required. The upgrade script sets the correct Java version automatically. Verify after upgrade:

java -version
  • Backup scope expanded: The configuration-backup.sh script now includes additional configuration files for license-service, intelligence, and logserver-store. Run a post-upgrade backup to capture the full scope:

bash /usr/share/logserver/utils/configuration-backup.sh

Post-upgrade verification:

systemctl status logserver logserver-gui logserver-probe intelligence intelligence-scheduler alert license-service skimmer e-doc --no-pager

Upgrade from Version 7.7.0

Standard upgrade path with minimal changes.

./install.sh -u

Post-upgrade verification:

  • Test new features accessibility

  • Verify all services functionality

  • Check log processing continuity

Upgrade from Version 7.6.0

Preferred Upgrade Steps for 7.6.0

  1. Run upgrade script:

./install.sh -u

Required Post Upgrade from Version 7.6.0

Breaking and major changes

  • Archive: Changed the default archives location to /usr/share/logserver-gui/data/archive/archives/ - please adjust external storage resource to this path [if used]. To customize the archive.archivefolderpath directive edit the /etc/logserver-gui/logserver-gui.yml file and restart the logserver-gui service.

sed -i 's|archive.archivefolderpath:.*|archive.archivefolderpath: "/usr/share/logserver-gui/data/archive/archives/"|' /etc/logserver-gui/logserver-gui.yml

systemctl restart logserver-gui
  • Network-Probe: Move required directives from /opt/license-service/license-service.conf to /opt/license-service/license-service.conf.rpmnew and replace license-service.conf then restart the license-service.

Upgrade from Version 7.5.0

Preferred Upgrade Steps for 7.5.0

  1. Run upgrade script:

./install.sh -u

Required Post Upgrade from Version 7.5.0

Breaking and major changes

  • User “logserver” will no longer be able to log into GUI. Use “admin” user instead. The update process will print the generated password for this new user. In case you have missed it you can run the following command on your main client node to recover the password:

/usr/share/logserver/utils/logserver-password-util.sh get_password -u admin -q

Upgrade from Version 7.4.2 / 7.4.3

Preferred Upgrade Steps for 7.4.2 / 7.4.3

  1. Run upgrade script:

./install.sh -u

Required Post Upgrade from Version 7.4.2 / 7.4.3

Breaking and major changes

  • Network-Probe replaces Logserver-Probe: follow the steps below.

LOGSERVER-PROBE:

  • Backup /etc/logserver-probe

cp -r /etc/logserver-probe /backup/logserver-probe-7.4-backup/
  • Uninstall old version:

Warning

This command permanently removes Network Probe configuration and data. Ensure you have a backup before proceeding.

yum versionlock delete logserver-probe-oss-7.17.11-1
yum remove logserver-probe-oss
rm -rf /etc/logserver-probe /var/lib/logserver-probe /usr/share/logserver-probe
  • Install the current Input Layer from scratch using sudo ./install.sh -i - Network-Probe Section

  • Restore from backup custom pipelines to /etc/logserver-probe/conf.d/

cp /backup/logserver-probe-7.4-backup/conf.d/* /etc/logserver-probe/conf.d/

ENERGYLOGSERVER

  • ./install.sh checks indexes compatibility before upgrading. If any problems exist, please contact product support to guide you through the upgrade process.

  • Move required directives from /etc/logserver/logserver.yml to /etc/logserver/logserver.yml.rpmnew and replace logserver.yml.

mv /etc/logserver/logserver.yml /etc/logserver/logserver.yml.backup
mv /etc/logserver/logserver.yml.rpmnew /etc/logserver/logserver.yml

LOGSERVER-GUI

  • Move required directives from /etc/logserver-gui/logserver-gui.yml to /etc/logserver-gui/logserver-gui.yml.rpmnew and replace logserver-gui.yml.

mv /etc/logserver-gui/logserver-gui.yml /etc/logserver-gui/logserver-gui.yml.backup
mv /etc/logserver-gui/logserver-gui.yml.rpmnew /etc/logserver-gui/logserver-gui.yml
  • Clear browser cache on client side.

LICENSE-SERVICE

  • If required, configure logserver_connection in /opt/license-service/license-service.conf.

  • Old configuration should be in /opt/license-service/license-service.conf.rpmsave. Do not replace license-service.conf with license-service.conf.rpmsave

EMPOWERED-AI (7.4.3 only)

  • Backup .intelligence_models, .intelligence_rule_configuration indices - if needed

  • Stop services:

systemctl stop empowered-ai
  • Delete old indices:

curl -XDELETE '127.0.0.1:9200/.intelligence_rule_configuration,.intelligence_models,.intelligence_results' -u $USER:$PASSWORD
  • Start services:

systemctl start empowered-ai

Upgrade from Version 7.4.1

Preferred Upgrade Steps for 7.4.1

  1. Run upgrade script:

./install.sh -u

No additional post-upgrade steps are required for this version.

Upgrade from Version 7.4.0

Preferred Upgrade Steps for 7.4.0

  1. Run upgrade script:

./install.sh -u

No additional post-upgrade steps are required for this version.

Upgrade from Version 7.3.0

Preferred Upgrade Steps for 7.3.0

  1. Run upgrade script:

./install.sh -u

Required Post Upgrade from Version 7.3.0

ENERGYLOGSERVER

  • ./install.sh checks indexes compatibility before upgrading. If any problems exist, please contact product support to guide you through the upgrade process.

  • Move required directives from /etc/logserver/logserver.yml to /etc/logserver/logserver.yml.rpmnew and replace logserver.yml.

LOGSERVER-GUI

  • Move required directives from /etc/logserver-gui/logserver-gui.yml to /etc/logserver-gui/logserver-gui.yml.rpmnew and replace logserver-gui.yml.

  • Clear browser cache on client side.

LOGSERVER-PROBE

  • Backup /etc/logserver-probe

  • Uninstall old version:

yum versionlock delete logserver-probe-oss-7.17.11-1
yum remove logserver-probe-oss
rm -rf /etc/logserver-probe /var/lib/logserver-probe /usr/share/logserver-probe
  • Install the current Input Layer from scratch using sudo ./install.sh -i - Network-Probe Section.

  • Restore from backup custom pipelines to /etc/logserver-probe/conf.d/

LICENSE-SERVICE

  • If required, configure logserver_connection in /opt/license-service/license-service.conf.

  • Old configuration should be in /opt/license-service/license-service.conf.rpmsave. Do not replace license-service.conf with license-service.conf.rpmsave

EMPOWERED-AI Migration (7.3.0 only):

curl -X POST "localhost:9200/_snapshot/backup_repo/intelligence_backup" -H 'Content-Type: application/json' -u $USER:$PASSWORD -d'
{
  "indices": ".intelligence_models,.intelligence_rule_configuration"
}'

systemctl stop empowered-ai
yum remove empowered-ai

./install.sh -u