<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Questions regarding Universal Forwarder upgrade prerequisites, backup, downtime, and CLI authentication in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Questions-regarding-Universal-Forwarder-upgrade-prerequisites/m-p/762065#M120754</link>
    <description>&lt;P&gt;1) What are the prerequisites and requirements for upgrading Splunk Universal Forwarder?&lt;BR /&gt;2)&amp;nbsp;We would appreciate it if you could provide the recommended backup and rollback procedures.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jul 2026 05:02:26 GMT</pubDate>
    <dc:creator>sri2splunk</dc:creator>
    <dc:date>2026-07-03T05:02:26Z</dc:date>
    <item>
      <title>Questions regarding Universal Forwarder upgrade prerequisites, backup, downtime, and CLI authentication</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Questions-regarding-Universal-Forwarder-upgrade-prerequisites/m-p/762065#M120754</link>
      <description>&lt;P&gt;1) What are the prerequisites and requirements for upgrading Splunk Universal Forwarder?&lt;BR /&gt;2)&amp;nbsp;We would appreciate it if you could provide the recommended backup and rollback procedures.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2026 05:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Questions-regarding-Universal-Forwarder-upgrade-prerequisites/m-p/762065#M120754</guid>
      <dc:creator>sri2splunk</dc:creator>
      <dc:date>2026-07-03T05:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Questions regarding Universal Forwarder upgrade prerequisites, backup, downtime, and CLI authentication</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Questions-regarding-Universal-Forwarder-upgrade-prerequisites/m-p/762066#M120755</link>
      <description>&lt;P class=""&gt;Hello,&lt;/P&gt;&lt;P&gt;Please find the answers below.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1) Prerequisites and requirements for upgrading Splunk Universal Forwarder&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Before upgrading the Splunk Universal Forwarder, it is recommended to verify the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Operating system compatibility:&lt;/STRONG&gt; Verify that the operating system is supported by the target Universal Forwarder version.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Supported upgrade path:&lt;/STRONG&gt; Review the supported upgrade path and any upgrade considerations for the target version.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;App/Add-on compatibility:&lt;/STRONG&gt; Verify the compatibility of any installed apps or add-ons with the target version by reviewing the respective Splunkbase pages.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Disk space:&lt;/STRONG&gt; Ensure sufficient disk space is available for the upgrade.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Release notes:&lt;/STRONG&gt; Review the release notes and known issues for the target version before proceeding.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Therefore, the understanding that the prerequisites primarily involve verifying operating system compatibility and installed app/add-on compatibility is correct. However, the supported upgrade path, available disk space, release notes, and any version-specific upgrade considerations should also be reviewed.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;References:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;About upgrading to 10.2 – READ THIS FIRST:&lt;BR /&gt;&lt;A class="" href="https://help.splunk.com/en/splunk-enterprise/administer/install-and-upgrade/10.2/upgrade-or-migrate-splunk-enterprise/about-upgrading-to-10.2-read-this-first" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise/administer/install-and-upgrade/10.2/upgrade-or-migrate-splunk-enterprise/about-upgrading-to-10.2-read-this-first&lt;/A&gt;&lt;/P&gt;&lt;P&gt;System requirements:&lt;BR /&gt;&lt;A class="" href="https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.2/plan-your-splunk-enterprise-installation/system-requirements-for-use-of-splunk-enterprise-on-premises" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.2/plan-your-splunk-enterprise-installation/system-requirements-for-use-of-splunk-enterprise-on-premises&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Upgrade the Universal Forwarder:&lt;BR /&gt;&lt;A class="" href="https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/universal-forwarder-manual/10.2/upgrade-or-uninstall-the-universal-forwarder/upgrade-the-universal-forwarder" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/universal-forwarder-manual/10.2/upgrade-or-uninstall-the-universal-forwarder/upgrade-the-universal-forwarder&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2) Recommended backup and rollback procedures&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Before upgrading the Universal Forwarder, it is recommended to back up the existing installation configuration, particularly the $SPLUNK_HOME/etc directory. This directory contains important configuration files such as inputs.conf, outputs.conf, deploymentclient.conf, server.conf, and any custom apps or local configurations.&lt;/P&gt;&lt;P&gt;If the Universal Forwarder is managed by a Deployment Server, it is also recommended to ensure that the relevant deployment apps are backed up on the Deployment Server.&lt;/P&gt;&lt;P&gt;If rollback is required, the general approach is:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Stop the Universal Forwarder service.&lt;/LI&gt;&lt;LI&gt;Reinstall the previous Universal Forwarder version.&lt;/LI&gt;&lt;LI&gt;Restore the backed-up configuration files, if necessary.&lt;/LI&gt;&lt;LI&gt;Start the Universal Forwarder service.&lt;/LI&gt;&lt;LI&gt;Verify that data forwarding resumes successfully.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Splunk normally preserves the existing configuration during an upgrade. However, maintaining a backup before the upgrade is recommended to support recovery if any issue occurs.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Reference:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Back up configuration information:&lt;BR /&gt;&lt;A class="" href="https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/administer-splunk-enterprise-with-configuration-files/back-up-configuration-information" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/administer-splunk-enterprise-with-configuration-files/back-up-configuration-information&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2026 05:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Questions-regarding-Universal-Forwarder-upgrade-prerequisites/m-p/762066#M120755</guid>
      <dc:creator>sri2splunk</dc:creator>
      <dc:date>2026-07-03T05:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Questions regarding Universal Forwarder upgrade prerequisites, backup, downtime, and CLI authentication</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Questions-regarding-Universal-Forwarder-upgrade-prerequisites/m-p/762067#M120756</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/317781"&gt;@sri2splunk&lt;/a&gt;&amp;nbsp;- Thanks for sharing Tip on Splunk Community. I'm accepting your answer as Accepted Solution, so future community member can get benefited from this. In the future when you share a Tip with both question and its answer, you can mark your own answer as a Accepted Solution as well so other users will be benefited or it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2026 09:05:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Questions-regarding-Universal-Forwarder-upgrade-prerequisites/m-p/762067#M120756</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2026-07-03T09:05:14Z</dc:date>
    </item>
  </channel>
</rss>

