<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder upgrade frequency best practices. in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699833#M28628</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262846" target="_blank"&gt;@PiotrAp&lt;/A&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's always better to use the latest possible version, with the following rules:&lt;/P&gt;&lt;P&gt;UF version must be the same or lower than the one on the Indexer or HF that receives data.&lt;/P&gt;&lt;P&gt;UF version must be compatible with the operative system you have on the server.&lt;/P&gt;&lt;P&gt;If you cannot use the latest version because your OS is old, search for the latest certified version; if you don't find it, ask to Splunk Support.&lt;/P&gt;&lt;P&gt;How often upgrade it: at least when the installed version is out of support, but a good planning could be&amp;nbsp; once a year.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 23 Sep 2024 13:02:36 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-09-23T13:02:36Z</dc:date>
    <item>
      <title>Universal Forwarder upgrade frequency best practices.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699807#M28626</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm looking for advise how often should I upgrade Splunk Universal Forwarder - what is the best practice for this.&lt;/P&gt;&lt;P&gt;In the&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.2.2406/Admin/UpgradeyourForwarders" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.2.2406/Admin/UpgradeyourForwarders&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;stays:&lt;/P&gt;&lt;P&gt;As a best practice, run the most recent forwarder version, even if the forwarder is a higher version number than your Splunk Cloud Platform environment.&lt;/P&gt;&lt;P&gt;But is it really good practice to install the latest version? How do you do this in your environment?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 09:17:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699807#M28626</guid>
      <dc:creator>PiotrAp</dc:creator>
      <dc:date>2024-09-23T09:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder upgrade frequency best practices.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699831#M28627</link>
      <description>&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 13:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699831#M28627</guid>
      <dc:creator>giuseppe</dc:creator>
      <dc:date>2024-09-23T13:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder upgrade frequency best practices.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699833#M28628</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262846" target="_blank"&gt;@PiotrAp&lt;/A&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's always better to use the latest possible version, with the following rules:&lt;/P&gt;&lt;P&gt;UF version must be the same or lower than the one on the Indexer or HF that receives data.&lt;/P&gt;&lt;P&gt;UF version must be compatible with the operative system you have on the server.&lt;/P&gt;&lt;P&gt;If you cannot use the latest version because your OS is old, search for the latest certified version; if you don't find it, ask to Splunk Support.&lt;/P&gt;&lt;P&gt;How often upgrade it: at least when the installed version is out of support, but a good planning could be&amp;nbsp; once a year.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 13:02:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699833#M28628</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-23T13:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder upgrade frequency best practices.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699870#M28630</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your reply.&lt;/P&gt;&lt;P&gt;So should I update it once a year? If so, should I install the latest possible version or use something like N-1? How do you do this in your environment? We have Splunk Cloud version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 15:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699870#M28630</guid>
      <dc:creator>PiotrAp</dc:creator>
      <dc:date>2024-09-23T15:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder upgrade frequency best practices.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699873#M28631</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262846"&gt;@PiotrAp&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if you haven't an intermediate HF, you should upgrade to the last Splunk Cloud Version.&lt;/P&gt;&lt;P&gt;If you have an intermediate HF, it must be aligned to the Splunk Cloud version, and UFs to the HF version.&lt;/P&gt;&lt;P&gt;I never use the approach ov n-1 version, I always install the last released version.&lt;/P&gt;&lt;P&gt;If you can, it's always better upgrate as soon as the new version is released, but I understand that's not possible in a large infrastructiure, so the frequency of once a year is a&amp;nbsp; good compromise between costs and update necessity.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 16:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699873#M28631</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-23T16:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder upgrade frequency best practices.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699876#M28632</link>
      <description>&lt;P&gt;Well... there are as many "good" answers as there are admins &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; And each approach has probably its pros and cons.&lt;/P&gt;&lt;P&gt;Regardless of the actual upgrade schedule it's important - especially if you have a big environment - to not just uncontrollably push a new version everywhere but phase the deployment - first some dev environment, then selected few pilot machines, only then the rest of environment. And be prepared to downgrade in case of problems.&lt;/P&gt;&lt;P&gt;And for me it's not as much about actual frequency of updates as much as triggers.&lt;/P&gt;&lt;P&gt;If there are some vulerabilities (important to you; not all vulnerabilities are exploitable in all environments) patched with new version - upgrade.&lt;/P&gt;&lt;P&gt;If there are new functionalities important to you now or in forseeable future - upgrade.&lt;/P&gt;&lt;P&gt;If there are important bug fixes - upgrade.&lt;/P&gt;&lt;P&gt;Otherwise - "if it ain't broke don't fix it". Mostly. It's good to stay within a maintained version range - you wouldn't want to use 6.x version nowadays unless you have really no other choice.&lt;/P&gt;&lt;P&gt;Of course as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; said - you're limited by what versions are supported by your OS and you can't - for example - install a 9.3UF on a RaspberryPi 2 or Windows 2008 32-bit because there is no such version available for those architectures.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 17:43:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699876#M28632</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-23T17:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder upgrade frequency best practices.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699907#M28634</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;SPAN&gt;Giuseppe!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 08:27:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/699907#M28634</guid>
      <dc:creator>PiotrAp</dc:creator>
      <dc:date>2024-09-24T08:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder upgrade frequency best practices.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/700436#M28652</link>
      <description>Hi&lt;BR /&gt;actually this has changed on 9.x. Currently you can have newer UF/HF versions than Splunk server or SCP have.&lt;BR /&gt;&lt;BR /&gt;Earlier (pre 9) it was instructed that sever must have higher or equal version than UF/HF/IHF.&lt;BR /&gt;&lt;BR /&gt;I prefer to wait some time after a new version has released to see if there is any issues with new version. Just like I do with server side. Usually you could/should do those upgrades e.g. couple of time per year like any other OS/other tools. Of course when there is any security issue then you should do updates out of you normal update cycle.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Sat, 28 Sep 2024 15:43:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/700436#M28652</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-09-28T15:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder upgrade frequency best practices.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/700493#M28671</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 08:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-upgrade-frequency-best-practices/m-p/700493#M28671</guid>
      <dc:creator>PiotrAp</dc:creator>
      <dc:date>2024-09-30T08:11:49Z</dc:date>
    </item>
  </channel>
</rss>

