Deployment Architecture

If I have a Splunk DS version 9.0.1, what is the oldest version of Splunk UF that I can control, please?

BlueSocket
Communicator

Dear All,

I have about 100 Splunk UFs at 7.0.1, 7.3.5, 8.1.5, 8.2.5 and 9.0.0.1 and they are NOT being managed by a Deployment Server. I need to get them all managed by a DS at v 9.0.1, so that I can manage my apps remotely and so that I can get around the latest DS security CVEs.

What is the oldest Splunk UF that a DS 9.0.1 can manage?

The latest version of the Forwarder compatibility document is not available (and it does not cover compatibility between DS and UFs, anyway).

Lastly, if I were to deploy a 8.2 DS, then would I be able to control the 9.0.0.1 UF?

Labels (2)
0 Karma
1 Solution

BlueSocket
Communicator

I have found the answer to my question in a different space:

https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/AboutupgradingREADTHISFIRST

In there, it says, "Confirm that all deployment clients in your network run version 7.0.0 or higher of Splunk Enterprise or the universal forwarder. You don't have to upgrade deployment clients to version 9.0.0, but they must be at version 7.0.0 or higher to communicate with version 9.0.0 deployment servers."

So the answer is "7.0.0 and above"!

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar... is the official support matrix. Based on this 7.x is supported. Probably also older versions is also working, but those combinations are not supported.

r. Ismo

0 Karma

BlueSocket
Communicator

I have found the answer to my question in a different space:

https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/AboutupgradingREADTHISFIRST

In there, it says, "Confirm that all deployment clients in your network run version 7.0.0 or higher of Splunk Enterprise or the universal forwarder. You don't have to upgrade deployment clients to version 9.0.0, but they must be at version 7.0.0 or higher to communicate with version 9.0.0 deployment servers."

So the answer is "7.0.0 and above"!

0 Karma

BlueSocket
Communicator

Thanks @isoutamo . That document is talking about the Forwarders to Indexers, but not DS, however, I am guessing that the compatibility between DS and Forwarders and Indexers and Forwarders goes hand-in-hand and that this is supported and therefore will work.

0 Karma
Get Updates on the Splunk Community!

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...