Getting Data In

Splunk Universal Forwarder Compatibility to Splunk Indexer 8.0.2

gebr
Explorer

Hi,

in the official compatibility matrix there is no column for Indexer 8.0.x anymore as its no longer supported.

https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

 

Does anyone know up to which version of the Universal Forwarder is compatibel with an 8.0.x Indexer (with an 8.0.x Heavy Forwarder infront) ?

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Ok. So your whole environment is not supported anymore so if it works, it works but if it doesn't noone will officially help you. Having said that - any relatively modern (7.0+) forwarder should work. If you use 9.x forwarders you'll have to disable configtracker input because you don't have corresponding index on 8.x indexers and the events would generate warning and possibly go to your last resort index if you have one configured.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @gebr 

As 8.0.x no longer supporrted by splunk as per support policy from  https://www.splunk.com/en_us/legal/splunk-software-support-policy.html#core 

I would suggest to upgarde your infra to last version of Splunk. e.g 9.0.x. 

if you are not able to upgrade for sometime , 

may be i would suggest to go for 8.0.1 splunk UF  or same version as HF/Indexer 

you can download from older version from https://www.splunk.com/en_us/download/previous-releases-universal-forwarder.html 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...