Getting Data In

Has there been a change with indexer and universal forwarder compatibility?

asherinb
Explorer

Earlier the Splunk docs read 6.0 indexers are backwards compatible with forwarders down to 4.x but now it says 6.0 indexers are backwards compatible with forwarders down to 5.x , is this a new change?

gkanapathy
Splunk Employee
Splunk Employee

No, they will continue to work in practice, but 4.x is no longer supported by Splunk, so there will be no fixes or help with problems, other than to suggest upgrading the forwarder. (In fact you can probably use 3.x forwarders to send to 6.1, but again, those forwarders are no longer supported.)

ppablo
Retired

Hi @asherinb

Can you post the documentation links you're referring to that shows conflicting information?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...