Getting Data In

Universal Forwarder and forward-compatibility

cboillot
Contributor

In our zest to upgrade our Universal Forwarders (UF) , we have seemed to inadvertently upgrade to a version newer than our indexer. We currently are running Splunk Version 6.4.4. The UF on some of the servers are now at 6.5.

With the best practices stating that it is "recommended that that indexers be at the same or higher version of Splunk Enterprise than the forwarders they are receiving data from," will we see any issues?

When they say same version, are they talking just the major or both major and minor releases?

0 Karma
1 Solution

rjthibod
Champion

With Forwarders, you generally only have to worry about major versions matching to the indexers (e.g., 6.X to 6.X), especially when looking only at data output from the Forwarder.

View solution in original post

0 Karma

woodcock
Esteemed Legend

I would say that they clearly mean "both" HOWEVER, as long as you do not turn on any new features, you should be just fine. I would not change ANYTHING else until you get the Indexers ahead of all forwarders. One of the big problems that you have right now is if you change something and something breaks and it is related to the Forwarders at all, you are going to get tremendous grief (and quote possibly a 'call us back after you upgrade your Indexers' response) from Splunk Support because you are not in a supported configuration.

rjthibod
Champion

With Forwarders, you generally only have to worry about major versions matching to the indexers (e.g., 6.X to 6.X), especially when looking only at data output from the Forwarder.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...