Getting Data In

Splunk universal forwarder upgrade from 4.3.x to 7.0

ikulcsar
Communicator

HI,

I'm looking for information about updating UFs from version 4.3.x to 7.0.
I checked Splunk docs (Forwarder Manual), but there are no version dependency requirements for the upgrade.

So the question: is supported (and safe) the one step upgrade from 4.3.x to 7.0? The conjecture that yes, can someone confirm it?

Regards,
István

0 Karma
1 Solution

lloydknight
Builder

Hello ikulcsar

I would highly suggest to download the currently installed 4.3.x as a backup installer in case you would want to revert when an issue arises and backup your current configurations before upgrading.

For some reason (by my experience on installing UFs on different types of OS), I have encountered some version incompatibility issues esp. on AIX and solved some of those by downgrading or upgrading the UF. Also check the release notes of the UF that you will install. After the installation/upgrade, always check splunkd.log for errors.

Hope it helps!

Thanks!

View solution in original post

0 Karma

lloydknight
Builder

Hello ikulcsar

I would highly suggest to download the currently installed 4.3.x as a backup installer in case you would want to revert when an issue arises and backup your current configurations before upgrading.

For some reason (by my experience on installing UFs on different types of OS), I have encountered some version incompatibility issues esp. on AIX and solved some of those by downgrading or upgrading the UF. Also check the release notes of the UF that you will install. After the installation/upgrade, always check splunkd.log for errors.

Hope it helps!

Thanks!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...