Getting Data In

UF and Platform version level compatibility with new timestamp issue

jeffbat
Path Finder

Just got the notification about the timestamp issue coming in Jan 2020.

Timestamp Issue

I am currently running 7.2.4.2 across my Indexers/Search Heads/Heavy Forwarders. I see that I can just change out the datetime.xml file on them to resolve the issue.

My main question is around the Universal Forwarder level, with my backend being 7.2.4; can I upgrade my forwarders to 7.2.9.1 and there be no issue? We are running a mixture of 6.6.3 and 7.2.4.2 forwarders now. I will be difficult for us to put in a change for our backend infrastructure of Splunk to 7.2.9.1 so changing the file out makes sense but we likely can get the forwarders set to be upgraded if there will not be any compatibility issues with it talking to a lower minor version.

thanks for any information.

0 Karma
1 Solution

satyenshah
Path Finder

Yes, version 7.2.9.1 forwarders are compatible with 7.2.4 indexers:
https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

We have a mix of UF versions ranging from 7.0 to 8.0.0, alongside indexers that have been are frequently updated, and have never run into an indexer-compatibility issue.

At the same time, you can get away without doing anything to the UFs, since the timestamp extraction / cooking of data happens downstream of the UF.

View solution in original post

0 Karma

satyenshah
Path Finder

Yes, version 7.2.9.1 forwarders are compatible with 7.2.4 indexers:
https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

We have a mix of UF versions ranging from 7.0 to 8.0.0, alongside indexers that have been are frequently updated, and have never run into an indexer-compatibility issue.

At the same time, you can get away without doing anything to the UFs, since the timestamp extraction / cooking of data happens downstream of the UF.

0 Karma

lmichalski_2
Explorer
  1. Could you add -f flag for copy inside scripts? Actually copying did not work for me, because original datetime.xml can have permissions=444. Without flag -f cp can return Permission denied. Or another way - chmod temporarily /opt/splunkforwarder/etc/datetime.xml to 644

I don't know yet if similar thing is needed for Windows UF
2. According to this https://stackoverflow.com/a/38285462 , could you add permissions for executing?

0 Karma

satyenshah
Path Finder

I fatfingered cp -rp by habit. Changed to cp -f. Thanks for the heads up!

0 Karma

jeffbat
Path Finder

That is what I thought, thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...