Getting Data In

Splunk upgrade on Heavy Forwarder from v6.4.0 to v7.3.1.1 (add-on version question)

km1986
Path Finder

Hello All,

 

We are upgrading Splunk Heavy Forwarder from  v6.4.0 to v7.3.1.1 and we were evaluating the need to upgrade add-ons installed on the HF to ensure compatibility with v7.3.x.

We have narrowed down the add-ons which require an upgrade on the HF, but are unsure if they need to be upgraded to the same version as HF on SH/IDX also (in Splunkcloud) for the field extraction to happen properly?

Below are the apps: Any guidance is appreciated, thanks.

https://splunkbase.splunk.com/app/1620/

https://splunkbase.splunk.com/app/1915/

https://splunkbase.splunk.com/app/1747/

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

In general, it's a good idea for all Splunk components to use the same version of a TA/app.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...