Deployment Architecture

Compatibility between forwarders and indexers

AaronMoorcroft
Communicator

Hi Guys,

I could do with upgrading all our forwarders, mainly 5.0.2 on Windows to the latest forwarder build 6.2.2, the potential issue being that our indexer is 5.0.2. This will be upgraded also but not for a while, so my question is if I go ahead and upgrade the current forwarders from 5.0.2 up to 6.2.2 will they continue to work with a 5.0.2 Indexer ?

Thank you

Tags (1)
0 Karma
1 Solution

MuS
Legend

Hi AaronMoorcroft,

check the docs http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Compatibilitybetweenforwardersandindexe... where you can find the following statement:

 6.x forwarders (universal/light/heavy) are backwards compatible down to 5.0.x indexers.

Hope that helps ...

cheers, MuS

View solution in original post

0 Karma

jeffland
SplunkTrust
SplunkTrust

It shouldn't be a problem to use 6.x forwarders with 5.x indexers, based on this documentation.

0 Karma

MuS
Legend

Hi AaronMoorcroft,

check the docs http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Compatibilitybetweenforwardersandindexe... where you can find the following statement:

 6.x forwarders (universal/light/heavy) are backwards compatible down to 5.0.x indexers.

Hope that helps ...

cheers, MuS

0 Karma

jeffland
SplunkTrust
SplunkTrust

Meh, you were seconds faster... 🙂

AaronMoorcroft
Communicator

cheers pal 🙂

0 Karma

AaronMoorcroft
Communicator

That's spot on, thank you very much for that, now I guess I have some work to do :$

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...