Getting Data In

Splunk 5.0.4 migration - Should the forwarder be stopped while migrating the indexer ?

spiketide
Engager

Hi Everyone,

First a few words about my setup.
I have a distributed setup with the following nodes

  1. Indexer
  2. Search Head
  3. Forwarder (Lets call this the 'Light Weight' forwarder )
  4. Job Scheduler

I have some devices whose logs are transferred using their forwarder (Lets call this the Universal Forwarder).

The universal forwarder send the logs to the light weight forwarder which just pass them on to the indexer.

Now, I am trying to migrate from Splunk 4.3 to Splunk 5.0. During this process, the splunk process on the indexer node should be stopped.

My question is, should the light weight forwarder also be stopped while migrating the indexer to prevent data loss? Will splunk keep the data in the pipe of the light weight forwarder when the indexer is down or will it keep on sending resulting in data loss?

0 Karma

lukejadamec
Super Champion

If you are using useAck=true then you should be OK. Otherwise you should stop the forwarder.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...