Deployment Architecture

Version compatibility - older search head thinks new indexer is 'not a Splunk server'

rgonzale6
Path Finder

Greetings - we have a Splunk 5.0.6 search head that we're trying to add a newer indexer (6.6.4) to the distributed search pool for - and the status reports "Not a Splunk server" for the new indexer.

Is there any guidance here? (Besides upgrade the 5.0.6, which we have some temporary logistical barriers against)

Thanks!

0 Karma

micahkemp
Champion

Unfortunately you are in unsupported territory. From the documentation:

The search heads must run the same or a later version from the peer nodes.

Despite wanting advice different from "upgrade your search head", that's likely your only viable option.

0 Karma

rgonzale6
Path Finder

That seems to be focused on a formal 'search head' in a clustered environment. In our case, our 'search head' is simply a splunk instance with our indexers added to its distributed search schema. I wonder if there's a compatibility difference...

0 Karma

harsmarvania57
Ultra Champion

@micahkemp is correct same rule applies to Distributed Environment, here is document for Distributed environment.

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...