What is best practice / recommended when deploying universal forwarders relative to the splunk indexers / base install? Can I use a 6.3 forwarder with a 6.2.x base?
It will probably work fine. That said the best practice is that the Indexer be at the same version or higher than the forwarder sending data.