Getting Data In

Upgrade Splunk Univeral forwarder on Exchange Server

schultet
Path Finder

I have Splunk Enterprise with Splunk App for Microsoft Exchange - I want to upgrade the Forwarders (and possible apps) to current versions if necessary.

1) Is it necessary? Benefits?

2) What is the Forwarder upgrade process? I'm hoping I just install the new forwarder with the MSI downloaded and it will not impact any of the Conf files. Current forwarder is 5.0.4.172409. I have Downloaded 6.2.2-2 MSI

Splunk Version............................................6.2.2
Splunk Build............................................255606
Current App............................................Splunk App for Microsoft Exchange
App Version............................................2.1.2-

3) I also see that I have the following apps installed on my Exchange server (single site exchange server)
TA-Exchange-2010-CAS
TA-Exchange-2010-HubTransport
TA-Exchange-2010-MailboxStore
TA-Windows-2008R2-Exchange-IIS

Should I also update these apps and does anyone have a process for it that preserves any settings that may have been updated in .conf files or elsewhere.

Thanks
Tom

0 Karma

neelamssantosh
Contributor

Hi Schultet,

Its good to upgrade to latest version but before that make sure that there are no Bugs in the latest version and and all the respective apps are supporting them. Forwarders are always compatible with later version indexers, so you do not need to upgrade them just because you've upgraded the indexers they're sending data to.

Its not necessary to update the apps too. if upgraded,check if the respective logs and fields are getting extracted as required.

In windows the best part is "double click" on the installer and it will get installed :).

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...