- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am new to Splunk and our UF has version 4.x. Since it's out of support, and we have Splunk version 6.0.7. I want to upgrade my UF from 4.x to 6.0.7.
Can someone help me with steps to do and from where I can get binaries of UF 6.0.7?
Thanks in advance.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi you do not really need to use same version of UF as Indexer. Refer this link to choose the latest version of UF as compare to your indexer:
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/Compatibilitybetweenforwardersandind...
To upgrade UNIX UF (change the version at the top as required):
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/Upgradethenixuniversalforwarder
To upgrade windows UF (change the version at the top as required):
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/UpgradetheWindowsuniversalforwarder
To download older releases of UF:
https://www.splunk.com/page/previous_releases/universalforwarder
let me know if this helps!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Splunk UF latest release is found under - https://www.splunk.com/en_us/download/universal-forwarder.html select the one to match your platform/OS.
Older releases are at https://www.splunk.com/page/previous_releases/universalforwarder
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Lakshman, based on your experience can you recommend which version of UF to use if my indexer is 6.0.7
Can I use 7.2.3???
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi you do not really need to use same version of UF as Indexer. Refer this link to choose the latest version of UF as compare to your indexer:
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/Compatibilitybetweenforwardersandind...
To upgrade UNIX UF (change the version at the top as required):
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/Upgradethenixuniversalforwarder
To upgrade windows UF (change the version at the top as required):
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/UpgradetheWindowsuniversalforwarder
To download older releases of UF:
https://www.splunk.com/page/previous_releases/universalforwarder
let me know if this helps!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Mayur, based on your experience can you recommend which version to use if my indexer is 6.0.7
Can I use 7.2.3???
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi
According to the table you can use 6.5.X UF. For latest version according to docs .forwarder can send data to this version of indexer after you change the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) version and cipher suite on the forwarder.
for upgrading to 6.5 you can use this doc:
https://docs.splunk.com/Documentation/Forwarder/6.5.0/Forwarder/Upgradethenixuniversalforwarder
