Getting Data In

Has there been a change with indexer and universal forwarder compatibility?

asherinb
Explorer

Earlier the Splunk docs read 6.0 indexers are backwards compatible with forwarders down to 4.x but now it says 6.0 indexers are backwards compatible with forwarders down to 5.x , is this a new change?

gkanapathy
Splunk Employee
Splunk Employee

No, they will continue to work in practice, but 4.x is no longer supported by Splunk, so there will be no fixes or help with problems, other than to suggest upgrading the forwarder. (In fact you can probably use 3.x forwarders to send to 6.1, but again, those forwarders are no longer supported.)

ppablo
Retired

Hi @asherinb

Can you post the documentation links you're referring to that shows conflicting information?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...