Getting Data In

Splunk Universal Forwarder Compatibility to Splunk Indexer 8.0.2

gebr
Explorer

Hi,

in the official compatibility matrix there is no column for Indexer 8.0.x anymore as its no longer supported.

https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

 

Does anyone know up to which version of the Universal Forwarder is compatibel with an 8.0.x Indexer (with an 8.0.x Heavy Forwarder infront) ?

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Ok. So your whole environment is not supported anymore so if it works, it works but if it doesn't noone will officially help you. Having said that - any relatively modern (7.0+) forwarder should work. If you use 9.x forwarders you'll have to disable configtracker input because you don't have corresponding index on 8.x indexers and the events would generate warning and possibly go to your last resort index if you have one configured.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @gebr 

As 8.0.x no longer supporrted by splunk as per support policy from  https://www.splunk.com/en_us/legal/splunk-software-support-policy.html#core 

I would suggest to upgarde your infra to last version of Splunk. e.g 9.0.x. 

if you are not able to upgrade for sometime , 

may be i would suggest to go for 8.0.1 splunk UF  or same version as HF/Indexer 

you can download from older version from https://www.splunk.com/en_us/download/previous-releases-universal-forwarder.html 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...