Hi - We are upgrading Splunk to 7.2.8 since 7.0 is out of support. the Universal forwarders are not mentioned in the Splunk support page and refers only to the Splunk enterprise. Does the UF need to be upgraded to be covered under Splunk Support?
Please refer to this doc to see the compatibility of Splunk Universal Forwarder and Splunk Enterprise Indexers:
Thanks... My questions was more towards Splunk able to provide support if in future the are issues. Keeping older version of Splunk forward will cover under Splunk Support policy?
As I am not in customer support team, I cannot speak for them. I would suggest to directly contact support team.