Deployment Architecture

If I have a Splunk DS version 9.0.1, what is the oldest version of Splunk UF that I can control, please?

BlueSocket
Contributor

Dear All,

I have about 100 Splunk UFs at 7.0.1, 7.3.5, 8.1.5, 8.2.5 and 9.0.0.1 and they are NOT being managed by a Deployment Server. I need to get them all managed by a DS at v 9.0.1, so that I can manage my apps remotely and so that I can get around the latest DS security CVEs.

What is the oldest Splunk UF that a DS 9.0.1 can manage?

The latest version of the Forwarder compatibility document is not available (and it does not cover compatibility between DS and UFs, anyway).

Lastly, if I were to deploy a 8.2 DS, then would I be able to control the 9.0.0.1 UF?

Labels (2)
0 Karma
1 Solution

BlueSocket
Contributor

I have found the answer to my question in a different space:

https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/AboutupgradingREADTHISFIRST

In there, it says, "Confirm that all deployment clients in your network run version 7.0.0 or higher of Splunk Enterprise or the universal forwarder. You don't have to upgrade deployment clients to version 9.0.0, but they must be at version 7.0.0 or higher to communicate with version 9.0.0 deployment servers."

So the answer is "7.0.0 and above"!

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar... is the official support matrix. Based on this 7.x is supported. Probably also older versions is also working, but those combinations are not supported.

r. Ismo

0 Karma

BlueSocket
Contributor

I have found the answer to my question in a different space:

https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/AboutupgradingREADTHISFIRST

In there, it says, "Confirm that all deployment clients in your network run version 7.0.0 or higher of Splunk Enterprise or the universal forwarder. You don't have to upgrade deployment clients to version 9.0.0, but they must be at version 7.0.0 or higher to communicate with version 9.0.0 deployment servers."

So the answer is "7.0.0 and above"!

0 Karma

BlueSocket
Contributor

Thanks @isoutamo . That document is talking about the Forwarders to Indexers, but not DS, however, I am guessing that the compatibility between DS and Forwarders and Indexers and Forwarders goes hand-in-hand and that this is supported and therefore will work.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...