Getting Data In

Upgrade Splunk Univeral forwarder on Exchange Server

schultet
Path Finder

I have Splunk Enterprise with Splunk App for Microsoft Exchange - I want to upgrade the Forwarders (and possible apps) to current versions if necessary.

1) Is it necessary? Benefits?

2) What is the Forwarder upgrade process? I'm hoping I just install the new forwarder with the MSI downloaded and it will not impact any of the Conf files. Current forwarder is 5.0.4.172409. I have Downloaded 6.2.2-2 MSI

Splunk Version............................................6.2.2
Splunk Build............................................255606
Current App............................................Splunk App for Microsoft Exchange
App Version............................................2.1.2-

3) I also see that I have the following apps installed on my Exchange server (single site exchange server)
TA-Exchange-2010-CAS
TA-Exchange-2010-HubTransport
TA-Exchange-2010-MailboxStore
TA-Windows-2008R2-Exchange-IIS

Should I also update these apps and does anyone have a process for it that preserves any settings that may have been updated in .conf files or elsewhere.

Thanks
Tom

0 Karma

neelamssantosh
Contributor

Hi Schultet,

Its good to upgrade to latest version but before that make sure that there are no Bugs in the latest version and and all the respective apps are supporting them. Forwarders are always compatible with later version indexers, so you do not need to upgrade them just because you've upgraded the indexers they're sending data to.

Its not necessary to update the apps too. if upgraded,check if the respective logs and fields are getting extracted as required.

In windows the best part is "double click" on the installer and it will get installed :).

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...