Getting Data In

Splunk Indexer and Universal Forwarder version compatibility

charlescywong
New Member

I noticed that Splunk official suggested us to keep the Indexer and UF using the same version (I am using 6.2.3). However, due to some issue, I need to upgrade the UF to 6.2.6 or 6.3. So doing, any compatibility issue will be introduced?

0 Karma
1 Solution

acharlieh
Influencer

No. This is spelled out in the docs: http://docs.splunk.com/Documentation/Splunk/6.3.3/Forwarding/Compatibilitybetweenforwardersandindexe...

  • A forwarder that runs version 6.x can send data to indexers that run version 5.0.x and later.
  • An indexer that runs version 6.x can accept data from forwarders that run version 4.3.x and later.

View solution in original post

0 Karma

acharlieh
Influencer

No. This is spelled out in the docs: http://docs.splunk.com/Documentation/Splunk/6.3.3/Forwarding/Compatibilitybetweenforwardersandindexe...

  • A forwarder that runs version 6.x can send data to indexers that run version 5.0.x and later.
  • An indexer that runs version 6.x can accept data from forwarders that run version 4.3.x and later.
0 Karma

charlescywong
New Member

Thanks Acharlieh !!

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...