I've got a 4.2.5 server and may be migrating to a 4.2.2 server. I've looked at the docs and they say that there's no way to downgrade but that you can install an earlier version. Does anyone know if it is safe to install 4.2.2 on top of our 4.2.5 data? I'd need to change the server and about eight forwarders.
It should be safe. It isn't supported to backport data, but there haven't been changes, and anyway, Splunk doesn't write or modify imported or copied over data buckets, so even in the worst case, the old version simply won't be able to read or search the new version's data. (Again, this is unlikely, since the data format didn't change.)