Earlier the Splunk docs read 6.0 indexers are backwards compatible with forwarders down to 4.x but now it says 6.0 indexers are backwards compatible with forwarders down to 5.x , is this a new change?
No, they will continue to work in practice, but 4.x is no longer supported by Splunk, so there will be no fixes or help with problems, other than to suggest upgrading the forwarder. (In fact you can probably use 3.x forwarders to send to 6.1, but again, those forwarders are no longer supported.)
Hi @asherinb
Can you post the documentation links you're referring to that shows conflicting information?