Getting Data In

6.1.3 forwarder compatibility

jgoodrow
New Member

I have a 6.1.3 forwarder installed on Windows XP with a 6.5.3 Indexer installed on Windows 10. I am unable to receive any data from the forwarder on the indexer. The compatibility matrix seems to show that the SSL and cypher suite need to be updated to allow communication between the two. Can anyone give some insight into how this is done?

0 Karma

DavidHourani
Super Champion

Hi @jgoodrow,

Have a look here, you'll be able to find the configuration you're looking for here : https://docs.splunk.com/Documentation/Splunk/6.5.3/Security/SetyourSSLversion

And this should help you troubleshooting :
https://docs.splunk.com/Documentation/Splunk/6.5.3/Security/Aboutsecuringdatafromforwarders

You're running on a pretty old version of Splunk that's no longer supported... Would be great if you can get that infrastructure updated 🙂

Cheers,
David

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...