Getting Data In

Updating to splunk 4.3 with existing 4.2 universal forwarders

neilstuartcraig
New Member

Hi all

We have an existing splunk install (2 x indexers, 1 x search head - all linux) on v 4.2 and quite a number (for various reasons) of servers (Windows 2008 R2) sending to the indexers which are using the v 4.2 universal forwarder.

Do i need to update all my universal forwarders to v 4.3 when updating the indexers and search head?

Also, if i install a v 4.3 universal forwarder which i configure to send to a 4.2 indexer, will it work/break?

Any advice gratefully received 🙂

Many thanks
Neil

0 Karma
1 Solution

Drainy
Champion

You don't need to upgrade straight away, there will be some benefits if you have a look at the updates page but otherwise if you have a look at the following link (referenced through the release notes for 4.3 and following through to details on upgrading UF's) it states that the UF's are backwards and forwards compatible with all current versions.

http://docs.splunk.com/Documentation/Splunk/4.3/Deploy/Deploymentoverview#Indexer_and_universal_forw...

View solution in original post

tpaulsen
Contributor

Are there any Security issues on the Universal Forwarder 4.2 to consider?

0 Karma

neilstuartcraig
New Member

Brilliant, thanks very much, i missed that point when reading the upgrade document yesterday.

0 Karma

Drainy
Champion

Thats alright. You won't be the first or last person to ask the question - there are quite a lot of docs to go through when upgrading 🙂

0 Karma

Drainy
Champion

You don't need to upgrade straight away, there will be some benefits if you have a look at the updates page but otherwise if you have a look at the following link (referenced through the release notes for 4.3 and following through to details on upgrading UF's) it states that the UF's are backwards and forwards compatible with all current versions.

http://docs.splunk.com/Documentation/Splunk/4.3/Deploy/Deploymentoverview#Indexer_and_universal_forw...

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...