<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal forwarder upgrade matrix in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665716#M13338</link>
    <description>&lt;P&gt;Forwarders are not as sensitive to particular upgrade path as "full" Splunk Enterprise instances are. I remember upgrading all the way straight from 7.2 to 9.0.&lt;/P&gt;&lt;P&gt;I'm not sure about as far back as 6.5 but with a reasonable backup of configuration I wouldn't expect many problems.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Oct 2023 20:09:18 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-10-20T20:09:18Z</dc:date>
    <item>
      <title>Universal forwarder upgrade matrix</title>
      <link>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665713#M13337</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have various splunk UFs running on windows ,unix machines . We are planning to upgrade all the versions to latest universal forwarder .&lt;/P&gt;&lt;P&gt;We have versions from : 6.5.0 to 8.2.7 .&lt;/P&gt;&lt;P&gt;Our plan to upgrade to 9.x&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone help intermediate versions to upgrade from 6.5.0 to 9.X&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 18:18:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665713#M13337</guid>
      <dc:creator>ssuluguri</dc:creator>
      <dc:date>2023-10-20T18:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder upgrade matrix</title>
      <link>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665716#M13338</link>
      <description>&lt;P&gt;Forwarders are not as sensitive to particular upgrade path as "full" Splunk Enterprise instances are. I remember upgrading all the way straight from 7.2 to 9.0.&lt;/P&gt;&lt;P&gt;I'm not sure about as far back as 6.5 but with a reasonable backup of configuration I wouldn't expect many problems.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 20:09:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665716#M13338</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-10-20T20:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder upgrade matrix</title>
      <link>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665722#M13339</link>
      <description>I’m not 100% sure if this is true or not? All UFs have fishbucket db for tracking ingested files. My guess is that this db needs some converting time by time. For that reason I propose to follow the same path with versions than you are following with enterprise. Other option is just backup your configuration then remove whole installation and start from scratch with old configuration. It’s your decision you want also save the UF’s GUID or not.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Fri, 20 Oct 2023 21:27:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665722#M13339</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-10-20T21:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder upgrade matrix</title>
      <link>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665783#M13341</link>
      <description>&lt;P&gt;I don't think fishbucket has been tampered with since the time it was moved from being an index to a local datastore. So I wouldn't expect problems here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2023 21:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665783#M13341</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-10-22T21:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder upgrade matrix</title>
      <link>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665793#M13342</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253157"&gt;@ssuluguri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per the doc -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwardersandindexers" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwardersandindexers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;the UF's should be able to upgrade directly from 6x to 9x.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;may we know the Splunk indexer version pls, thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT - Pls check this doc: &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/AboutupgradingREADTHISFIRST" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/AboutupgradingREADTHISFIRST&lt;/A&gt;&lt;BR /&gt;it is suggesting.... "Upgrading a universal forwarder directly to version 9.0 is supported from versions 8.1.x and higher."&lt;BR /&gt;&lt;BR /&gt;So, better you upgrade from 6x to 8.1x and then to 9.0.x, thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 03:26:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665793#M13342</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-10-23T03:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder upgrade matrix</title>
      <link>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665924#M13346</link>
      <description>&lt;P&gt;We are on splunk platform .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have server reporting to on prem Deployment servers and outputs configured to send cloud indexers .&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 21:27:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-forwarder-upgrade-matrix/m-p/665924#M13346</guid>
      <dc:creator>ssuluguri</dc:creator>
      <dc:date>2023-10-23T21:27:22Z</dc:date>
    </item>
  </channel>
</rss>

