Getting Data In

Compatibility between forward linux server 32 bit and indexer version 7.2.6

vn0qhul
New Member

¿Is there an incompatibility problem between the Linux 32 bit agent version (splunkforwarder-6.6.12-ff1b28d42e4c-Linux-i686) and the indexer version (7.2.6 Splunk Enterprise)? or are they fully compatible?.

I need to read logs from a 32 bit linux server, the indexer I have is splunk enterprise version 7.2.6, ¿what version of forwarder should I use?.

0 Karma
1 Solution

mstephenson716
Explorer

It looks like these versions are partially compatible, in that event data should be forward-able.

Here is a compatibility matrix for the versions you mentioned.
https://docs.splunk.com/Documentation/Forwarder/7.3.2/Forwarder/Compatibilitybetweenforwardersandind...

And a list of known issues for the forwarder version you mentioned.
https://docs.splunk.com/Documentation/Forwarder/6.6.12/Forwarder/KnownIssues

View solution in original post

0 Karma

mstephenson716
Explorer

It looks like these versions are partially compatible, in that event data should be forward-able.

Here is a compatibility matrix for the versions you mentioned.
https://docs.splunk.com/Documentation/Forwarder/7.3.2/Forwarder/Compatibilitybetweenforwardersandind...

And a list of known issues for the forwarder version you mentioned.
https://docs.splunk.com/Documentation/Forwarder/6.6.12/Forwarder/KnownIssues

0 Karma

vn0qhul
New Member

Hello mstephenson716

thanks for your time and for the information.

regards.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...