Deployment Architecture

If I have a Splunk DS version 9.0.1, what is the oldest version of Splunk UF that I can control, please?

BlueSocket
Contributor

Dear All,

I have about 100 Splunk UFs at 7.0.1, 7.3.5, 8.1.5, 8.2.5 and 9.0.0.1 and they are NOT being managed by a Deployment Server. I need to get them all managed by a DS at v 9.0.1, so that I can manage my apps remotely and so that I can get around the latest DS security CVEs.

What is the oldest Splunk UF that a DS 9.0.1 can manage?

The latest version of the Forwarder compatibility document is not available (and it does not cover compatibility between DS and UFs, anyway).

Lastly, if I were to deploy a 8.2 DS, then would I be able to control the 9.0.0.1 UF?

Labels (2)
0 Karma
1 Solution

BlueSocket
Contributor

I have found the answer to my question in a different space:

https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/AboutupgradingREADTHISFIRST

In there, it says, "Confirm that all deployment clients in your network run version 7.0.0 or higher of Splunk Enterprise or the universal forwarder. You don't have to upgrade deployment clients to version 9.0.0, but they must be at version 7.0.0 or higher to communicate with version 9.0.0 deployment servers."

So the answer is "7.0.0 and above"!

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar... is the official support matrix. Based on this 7.x is supported. Probably also older versions is also working, but those combinations are not supported.

r. Ismo

0 Karma

BlueSocket
Contributor

I have found the answer to my question in a different space:

https://docs.splunk.com/Documentation/Splunk/9.0.0/Installation/AboutupgradingREADTHISFIRST

In there, it says, "Confirm that all deployment clients in your network run version 7.0.0 or higher of Splunk Enterprise or the universal forwarder. You don't have to upgrade deployment clients to version 9.0.0, but they must be at version 7.0.0 or higher to communicate with version 9.0.0 deployment servers."

So the answer is "7.0.0 and above"!

0 Karma

BlueSocket
Contributor

Thanks @isoutamo . That document is talking about the Forwarders to Indexers, but not DS, however, I am guessing that the compatibility between DS and Forwarders and Indexers and Forwarders goes hand-in-hand and that this is supported and therefore will work.

0 Karma
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...