All Apps and Add-ons

Splunk stream forwarder versions?

mux
Explorer

We are running Splunk stream 6.5.1 on Splunk Enterprise 6.4.1 but most of our forwarders are still running on 5.0.5. I am planning to upgrade them later this year but I wanted to find out if Splunk stream can run on a forwarder of that version or not, I couldn't find anything on the web about the forwarder versions for the app.

Thanks, Mark.

0 Karma

dgrubb_splunk
Splunk Employee
Splunk Employee

Stream requirements will be contained on SplunkBase or in the App documentation:

Splunkbase
https://splunkbase.splunk.com/app/1809/

Stream Documentation:

http://docs.splunk.com/Documentation/StreamApp/6.5.1/DeployStreamApp/Deploymentrequirements#Splunk_E...

Splunk Enterprise version requirements
Splunk App for Stream runs on Splunk Enterprise. Before you install Splunk App for Stream, make sure that you are running the appropriate version of Splunk Enterprise.
Splunk App for Stream version 6.4.x and 6.5.0 require Splunk Enterprise version 6.3.0 or later.
For search head clustering, Splunk App for Stream version 6.5.0 requires Splunk Enterprise version 6.3.1 or later.
Independent deployment of the stream forwarder (streamfwd) 6.5.0 binary on a search head requires Splunk Enterprise version 6.3.1 or later.

csharp_splunk
Splunk Employee
Splunk Employee

Anything that supports modular inputs should work. I wouldn't go so far as to say we officially support forwarders that old, but I am aware of at least one customer that was successful doing this some time back. In Stream 6.5.1 on Linux, you also have the option of running the stream forwarder independently of the Splunk forwarder, so that may be worth consideration as well.

http://docs.splunk.com/Documentation/StreamApp/6.5.1/DeployStreamApp/InstallStreamForwarderonindepen...

Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...