Deployment Architecture

Version compatibility - older search head thinks new indexer is 'not a Splunk server'

rgonzale6
Path Finder

Greetings - we have a Splunk 5.0.6 search head that we're trying to add a newer indexer (6.6.4) to the distributed search pool for - and the status reports "Not a Splunk server" for the new indexer.

Is there any guidance here? (Besides upgrade the 5.0.6, which we have some temporary logistical barriers against)

Thanks!

0 Karma

micahkemp
Champion

Unfortunately you are in unsupported territory. From the documentation:

The search heads must run the same or a later version from the peer nodes.

Despite wanting advice different from "upgrade your search head", that's likely your only viable option.

0 Karma

rgonzale6
Path Finder

That seems to be focused on a formal 'search head' in a clustered environment. In our case, our 'search head' is simply a splunk instance with our indexers added to its distributed search schema. I wonder if there's a compatibility difference...

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

@micahkemp is correct same rule applies to Distributed Environment, here is document for Distributed environment.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.