Deployment Architecture

Version compatibility - older search head thinks new indexer is 'not a Splunk server'

rgonzale6
Path Finder

Greetings - we have a Splunk 5.0.6 search head that we're trying to add a newer indexer (6.6.4) to the distributed search pool for - and the status reports "Not a Splunk server" for the new indexer.

Is there any guidance here? (Besides upgrade the 5.0.6, which we have some temporary logistical barriers against)

Thanks!

0 Karma

micahkemp
Champion

Unfortunately you are in unsupported territory. From the documentation:

The search heads must run the same or a later version from the peer nodes.

Despite wanting advice different from "upgrade your search head", that's likely your only viable option.

0 Karma

rgonzale6
Path Finder

That seems to be focused on a formal 'search head' in a clustered environment. In our case, our 'search head' is simply a splunk instance with our indexers added to its distributed search schema. I wonder if there's a compatibility difference...

0 Karma

harsmarvania57
Ultra Champion

@micahkemp is correct same rule applies to Distributed Environment, here is document for Distributed environment.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...