<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: upgrade splunk forwarder in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/upgrade-splunk-forwarder/m-p/197293#M23629</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;You should upgrade at least to version 5.x&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;6.x indexers are backwards compatible with forwarders down to 5.0.x.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Compatibilitybetweenforwardersandindexers"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Compatibilitybetweenforwardersandindexers&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And, as a best practice you should have them in 6.x&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;As a best practice, it is recommended that indexers be at the same or higher version level than the forwarders they're receiving data from.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Fri, 07 Nov 2014 08:15:12 GMT</pubDate>
    <dc:creator>gfuente</dc:creator>
    <dc:date>2014-11-07T08:15:12Z</dc:date>
    <item>
      <title>upgrade splunk forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/upgrade-splunk-forwarder/m-p/197292#M23628</link>
      <description>&lt;P&gt;Hi there, i am upgrading my splunk server to version 6. however, i have multiple splunk forwarders (abt 300) in different versions, from v4.x to v6.&lt;/P&gt;

&lt;P&gt;i know other has asked something similar before. if i am going to choose one version, which one will it be ?&lt;/P&gt;

&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2014 08:10:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/upgrade-splunk-forwarder/m-p/197292#M23628</guid>
      <dc:creator>watzson</dc:creator>
      <dc:date>2014-11-07T08:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: upgrade splunk forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/upgrade-splunk-forwarder/m-p/197293#M23629</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;You should upgrade at least to version 5.x&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;6.x indexers are backwards compatible with forwarders down to 5.0.x.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Compatibilitybetweenforwardersandindexers"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Compatibilitybetweenforwardersandindexers&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And, as a best practice you should have them in 6.x&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;As a best practice, it is recommended that indexers be at the same or higher version level than the forwarders they're receiving data from.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2014 08:15:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/upgrade-splunk-forwarder/m-p/197293#M23629</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2014-11-07T08:15:12Z</dc:date>
    </item>
  </channel>
</rss>

