Getting Data In

Can you help us with our issue involving a Splunk Universal Forwarder Upgrade?

anandhalagarasa
Path Finder

Our Splunk Enterprise Systems ( Cluster Master, Indexers, Search Head and Heavy Forwarders .Deployment Master ) are running with Splunk 7.0.7 version.

So, we are planning to upgrade our Splunk Universal Forwarders for both the OS (Windows & Linux) from 6.5.0 to 7.0.7.

So my question is: can we directly upgrade our Splunk Universal Forwarders from 6.5.0 to 7.0.7 or do we need to upgrade something like from 6.5.0 to 7.0.0 and then to 7.0.7?

Kindly share your thoughts on the issue.

0 Karma
1 Solution

echalex
Builder

Hello anandhalagarasan ,

Going directly to 7.0.7 should not be a problem. The extra steps are usually only needed to upgrade between major releases. (And I think it's less of an issue with the Universal Forwarder, than it is with the full version.) For example, Splunk Enterprise below 6.5 needs to be upgraded to 6.5.x before upgrading to 7.x, but 6.5.9 is fine and you wouldn't need to go through 6.5.0.

So in your case, upgrading directly to 7.0.7 is fine.

View solution in original post

0 Karma

echalex
Builder

Hello anandhalagarasan ,

Going directly to 7.0.7 should not be a problem. The extra steps are usually only needed to upgrade between major releases. (And I think it's less of an issue with the Universal Forwarder, than it is with the full version.) For example, Splunk Enterprise below 6.5 needs to be upgraded to 6.5.x before upgrading to 7.x, but 6.5.9 is fine and you wouldn't need to go through 6.5.0.

So in your case, upgrading directly to 7.0.7 is fine.

0 Karma

anandhalagarasa
Path Finder

Thank you for your prompt response. Much appreciated.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...