Getting Data In

Upgrade Splunk Univeral forwarder on Exchange Server

schultet
Path Finder

I have Splunk Enterprise with Splunk App for Microsoft Exchange - I want to upgrade the Forwarders (and possible apps) to current versions if necessary.

1) Is it necessary? Benefits?

2) What is the Forwarder upgrade process? I'm hoping I just install the new forwarder with the MSI downloaded and it will not impact any of the Conf files. Current forwarder is 5.0.4.172409. I have Downloaded 6.2.2-2 MSI

Splunk Version............................................6.2.2
Splunk Build............................................255606
Current App............................................Splunk App for Microsoft Exchange
App Version............................................2.1.2-

3) I also see that I have the following apps installed on my Exchange server (single site exchange server)
TA-Exchange-2010-CAS
TA-Exchange-2010-HubTransport
TA-Exchange-2010-MailboxStore
TA-Windows-2008R2-Exchange-IIS

Should I also update these apps and does anyone have a process for it that preserves any settings that may have been updated in .conf files or elsewhere.

Thanks
Tom

0 Karma

neelamssantosh
Contributor

Hi Schultet,

Its good to upgrade to latest version but before that make sure that there are no Bugs in the latest version and and all the respective apps are supporting them. Forwarders are always compatible with later version indexers, so you do not need to upgrade them just because you've upgraded the indexers they're sending data to.

Its not necessary to update the apps too. if upgraded,check if the respective logs and fields are getting extracted as required.

In windows the best part is "double click" on the installer and it will get installed :).

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...