Deployment Architecture

4.3.3 Search Heads with 4.2.1 Indexers?

jbarteet
Engager

Greetings,

I have a distributed environment with 13 indexers and a pair of search heads with pooled searches enabled, all running Splunk v4.2.1

I'm sizing up the task of upgrading this infrastructure to 4.3.3, and It looks like the way to go about this is to remove the search heads from the pool, update them, and then have the search heads rejoin the pool. THEN, after your search heads are all copacetic, you go and upgrade your indexers one at a time.

I'm looking at breaking up the upgrade project over at least two outages.

Here's my question: Can the 4.3.3 search heads run with the 4.2.1 indexers without any issues?

In the Distributed Deployment Manual for 4.3.3, it alludes to this with a footnote reading:

"Note: Search heads running the latest version of Splunk can communicate with indexers running earlier versions of Splunk"

There's no adverse affect of running 4.3.3 search heads on 4.2.1 indexers at all ?

I'm wondering if I can go a week or so between the tasks of upgrading the Search Heads and the Indxers.

Thank you, Splunk Brethren!

Tags (1)
0 Karma
1 Solution

joshd
Builder

I ran a 4.3.x search head against a 4.2.x indexer for a while without any issues... of course you will not be able to take advantage of any of the 4.3.x features until you upgrade your indexers 🙂

View solution in original post

0 Karma

joshd
Builder

I ran a 4.3.x search head against a 4.2.x indexer for a while without any issues... of course you will not be able to take advantage of any of the 4.3.x features until you upgrade your indexers 🙂

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...