Deployment Architecture

Version compatibility - older search head thinks new indexer is 'not a Splunk server'

rgonzale6
Path Finder

Greetings - we have a Splunk 5.0.6 search head that we're trying to add a newer indexer (6.6.4) to the distributed search pool for - and the status reports "Not a Splunk server" for the new indexer.

Is there any guidance here? (Besides upgrade the 5.0.6, which we have some temporary logistical barriers against)

Thanks!

0 Karma

micahkemp
Champion

Unfortunately you are in unsupported territory. From the documentation:

The search heads must run the same or a later version from the peer nodes.

Despite wanting advice different from "upgrade your search head", that's likely your only viable option.

0 Karma

rgonzale6
Path Finder

That seems to be focused on a formal 'search head' in a clustered environment. In our case, our 'search head' is simply a splunk instance with our indexers added to its distributed search schema. I wonder if there's a compatibility difference...

0 Karma

harsmarvania57
Ultra Champion

@micahkemp is correct same rule applies to Distributed Environment, here is document for Distributed environment.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...