Getting Data In

Upgrade Splunk Univeral forwarder on Exchange Server

schultet
Path Finder

I have Splunk Enterprise with Splunk App for Microsoft Exchange - I want to upgrade the Forwarders (and possible apps) to current versions if necessary.

1) Is it necessary? Benefits?

2) What is the Forwarder upgrade process? I'm hoping I just install the new forwarder with the MSI downloaded and it will not impact any of the Conf files. Current forwarder is 5.0.4.172409. I have Downloaded 6.2.2-2 MSI

Splunk Version............................................6.2.2
Splunk Build............................................255606
Current App............................................Splunk App for Microsoft Exchange
App Version............................................2.1.2-

3) I also see that I have the following apps installed on my Exchange server (single site exchange server)
TA-Exchange-2010-CAS
TA-Exchange-2010-HubTransport
TA-Exchange-2010-MailboxStore
TA-Windows-2008R2-Exchange-IIS

Should I also update these apps and does anyone have a process for it that preserves any settings that may have been updated in .conf files or elsewhere.

Thanks
Tom

0 Karma

neelamssantosh
Contributor

Hi Schultet,

Its good to upgrade to latest version but before that make sure that there are no Bugs in the latest version and and all the respective apps are supporting them. Forwarders are always compatible with later version indexers, so you do not need to upgrade them just because you've upgraded the indexers they're sending data to.

Its not necessary to update the apps too. if upgraded,check if the respective logs and fields are getting extracted as required.

In windows the best part is "double click" on the installer and it will get installed :).

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...