Deployment Architecture

Version compatibility - older search head thinks new indexer is 'not a Splunk server'

rgonzale6
Path Finder

Greetings - we have a Splunk 5.0.6 search head that we're trying to add a newer indexer (6.6.4) to the distributed search pool for - and the status reports "Not a Splunk server" for the new indexer.

Is there any guidance here? (Besides upgrade the 5.0.6, which we have some temporary logistical barriers against)

Thanks!

0 Karma

micahkemp
Champion

Unfortunately you are in unsupported territory. From the documentation:

The search heads must run the same or a later version from the peer nodes.

Despite wanting advice different from "upgrade your search head", that's likely your only viable option.

0 Karma

rgonzale6
Path Finder

That seems to be focused on a formal 'search head' in a clustered environment. In our case, our 'search head' is simply a splunk instance with our indexers added to its distributed search schema. I wonder if there's a compatibility difference...

0 Karma

harsmarvania57
Ultra Champion

@micahkemp is correct same rule applies to Distributed Environment, here is document for Distributed environment.

0 Karma
Get Updates on the Splunk Community!

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

[Coming Soon] Splunk Observability Cloud - Enhanced navigation with a modern look and ...

We are excited to introduce our enhanced UI that brings together AppDynamics and Splunk Observability. This is ...