Deployment Architecture

If I have a Splunk DS version 9.0.1, what is the oldest version of Splunk UF that I can control, please?

BlueSocket
Contributor

Dear All,

I have about 100 Splunk UFs at 7.0.1, 7.3.5, 8.1.5, 8.2.5 and 9.0.0.1 and they are NOT being managed by a Deployment Server. I need to get them all managed by a DS at v 9.0.1, so that I can manage my apps remotely and so that I can get around the latest DS security CVEs.

What is the oldest Splunk UF that a DS 9.0.1 can manage?

The latest version of the Forwarder compatibility document is not available (and it does not cover compatibility between DS and UFs, anyway).

Lastly, if I were to deploy a 8.2 DS, then would I be able to control the 9.0.0.1 UF?

Labels (2)
0 Karma
1 Solution

BlueSocket
Contributor

I have found the answer to my question in a different space:

https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/AboutupgradingREADTHISFIRST

In there, it says, "Confirm that all deployment clients in your network run version 7.0.0 or higher of Splunk Enterprise or the universal forwarder. You don't have to upgrade deployment clients to version 9.0.0, but they must be at version 7.0.0 or higher to communicate with version 9.0.0 deployment servers."

So the answer is "7.0.0 and above"!

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar... is the official support matrix. Based on this 7.x is supported. Probably also older versions is also working, but those combinations are not supported.

r. Ismo

0 Karma

BlueSocket
Contributor

I have found the answer to my question in a different space:

https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/AboutupgradingREADTHISFIRST

In there, it says, "Confirm that all deployment clients in your network run version 7.0.0 or higher of Splunk Enterprise or the universal forwarder. You don't have to upgrade deployment clients to version 9.0.0, but they must be at version 7.0.0 or higher to communicate with version 9.0.0 deployment servers."

So the answer is "7.0.0 and above"!

0 Karma

BlueSocket
Contributor

Thanks @isoutamo . That document is talking about the Forwarders to Indexers, but not DS, however, I am guessing that the compatibility between DS and Forwarders and Indexers and Forwarders goes hand-in-hand and that this is supported and therefore will work.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...