Deployment Architecture

Compatibility between forwarders and indexers

AaronMoorcroft
Communicator

Hi Guys,

I could do with upgrading all our forwarders, mainly 5.0.2 on Windows to the latest forwarder build 6.2.2, the potential issue being that our indexer is 5.0.2. This will be upgraded also but not for a while, so my question is if I go ahead and upgrade the current forwarders from 5.0.2 up to 6.2.2 will they continue to work with a 5.0.2 Indexer ?

Thank you

Tags (1)
0 Karma
1 Solution

MuS
Legend

Hi AaronMoorcroft,

check the docs http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Compatibilitybetweenforwardersandindexe... where you can find the following statement:

 6.x forwarders (universal/light/heavy) are backwards compatible down to 5.0.x indexers.

Hope that helps ...

cheers, MuS

View solution in original post

0 Karma

jeffland
SplunkTrust
SplunkTrust

It shouldn't be a problem to use 6.x forwarders with 5.x indexers, based on this documentation.

0 Karma

MuS
Legend

Hi AaronMoorcroft,

check the docs http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Compatibilitybetweenforwardersandindexe... where you can find the following statement:

 6.x forwarders (universal/light/heavy) are backwards compatible down to 5.0.x indexers.

Hope that helps ...

cheers, MuS

0 Karma

jeffland
SplunkTrust
SplunkTrust

Meh, you were seconds faster... 🙂

AaronMoorcroft
Communicator

cheers pal 🙂

0 Karma

AaronMoorcroft
Communicator

That's spot on, thank you very much for that, now I guess I have some work to do :$

0 Karma
Get Updates on the Splunk Community!

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...