Getting Data In

Universal Forwarder and forward-compatibility

cboillot
Contributor

In our zest to upgrade our Universal Forwarders (UF) , we have seemed to inadvertently upgrade to a version newer than our indexer. We currently are running Splunk Version 6.4.4. The UF on some of the servers are now at 6.5.

With the best practices stating that it is "recommended that that indexers be at the same or higher version of Splunk Enterprise than the forwarders they are receiving data from," will we see any issues?

When they say same version, are they talking just the major or both major and minor releases?

0 Karma
1 Solution

rjthibod
Champion

With Forwarders, you generally only have to worry about major versions matching to the indexers (e.g., 6.X to 6.X), especially when looking only at data output from the Forwarder.

View solution in original post

0 Karma

woodcock
Esteemed Legend

I would say that they clearly mean "both" HOWEVER, as long as you do not turn on any new features, you should be just fine. I would not change ANYTHING else until you get the Indexers ahead of all forwarders. One of the big problems that you have right now is if you change something and something breaks and it is related to the Forwarders at all, you are going to get tremendous grief (and quote possibly a 'call us back after you upgrade your Indexers' response) from Splunk Support because you are not in a supported configuration.

rjthibod
Champion

With Forwarders, you generally only have to worry about major versions matching to the indexers (e.g., 6.X to 6.X), especially when looking only at data output from the Forwarder.

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...