Getting Data In
Highlighted

Can my Splunk 6.2.0 indexer work with a 6.2.9 light forwarder?

Explorer

I tried reading past posts, but cannot find a definitive answer.

Question: Currently, both my indexer and light forwarder is v6.2.0. There is a DROWN vulnerability with the LF and need to be upgraded. Can my indexer v6.2.0 work with LF v6.2.9?

0 Karma
Highlighted

Re: Can my Splunk 6.2.0 indexer work with a 6.2.9 light forwarder?

Builder
0 Karma
Highlighted

Re: Can my Splunk 6.2.0 indexer work with a 6.2.9 light forwarder?

Explorer

Thanks Jmallorquin. I saw that thread and my understanding is yes, indexer 6.2.0 is compatible with LF 6.2.9.

Is my understanding correct?

0 Karma
Highlighted

Re: Can my Splunk 6.2.0 indexer work with a 6.2.9 light forwarder?

Ultra Champion

The documentation is good ; -)

It says -

  • A forwarder that is version 6.0 or later can send data to an indexer that is version 5.0 or later of Splunk Enterprise.
  • An indexer that is version 6.0 or later of Splunk Enterprise can receive data from a forwarder that is version 4.3 or later.

You should be just fine.

0 Karma