I am new to Splunk and our UF has version 4.x. Since it's out of support, and we have Splunk version 6.0.7. I want to upgrade my UF from 4.x to 6.0.7.
Can someone help me with steps to do and from where I can get binaries of UF 6.0.7?
Thanks in advance.
Hi you do not really need to use same version of UF as Indexer. Refer this link to choose the latest version of UF as compare to your indexer:
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/Compatibilitybetweenforwardersandind...
To upgrade UNIX UF (change the version at the top as required):
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/Upgradethenixuniversalforwarder
To upgrade windows UF (change the version at the top as required):
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/UpgradetheWindowsuniversalforwarder
To download older releases of UF:
https://www.splunk.com/page/previous_releases/universalforwarder
let me know if this helps!
Splunk UF latest release is found under - https://www.splunk.com/en_us/download/universal-forwarder.html select the one to match your platform/OS.
Older releases are at https://www.splunk.com/page/previous_releases/universalforwarder
Thanks Lakshman, based on your experience can you recommend which version of UF to use if my indexer is 6.0.7
Can I use 7.2.3???
Hi you do not really need to use same version of UF as Indexer. Refer this link to choose the latest version of UF as compare to your indexer:
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/Compatibilitybetweenforwardersandind...
To upgrade UNIX UF (change the version at the top as required):
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/Upgradethenixuniversalforwarder
To upgrade windows UF (change the version at the top as required):
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/UpgradetheWindowsuniversalforwarder
To download older releases of UF:
https://www.splunk.com/page/previous_releases/universalforwarder
let me know if this helps!
Hi Mayur, based on your experience can you recommend which version to use if my indexer is 6.0.7
Can I use 7.2.3???
Hi
According to the table you can use 6.5.X UF. For latest version according to docs .forwarder can send data to this version of indexer after you change the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) version and cipher suite on the forwarder.
for upgrading to 6.5 you can use this doc:
https://docs.splunk.com/Documentation/Forwarder/6.5.0/Forwarder/Upgradethenixuniversalforwarder