Getting Data In

Upgrade Splunk Univeral forwarder on Exchange Server

schultet
Path Finder

I have Splunk Enterprise with Splunk App for Microsoft Exchange - I want to upgrade the Forwarders (and possible apps) to current versions if necessary.

1) Is it necessary? Benefits?

2) What is the Forwarder upgrade process? I'm hoping I just install the new forwarder with the MSI downloaded and it will not impact any of the Conf files. Current forwarder is 5.0.4.172409. I have Downloaded 6.2.2-2 MSI

Splunk Version............................................6.2.2
Splunk Build............................................255606
Current App............................................Splunk App for Microsoft Exchange
App Version............................................2.1.2-

3) I also see that I have the following apps installed on my Exchange server (single site exchange server)
TA-Exchange-2010-CAS
TA-Exchange-2010-HubTransport
TA-Exchange-2010-MailboxStore
TA-Windows-2008R2-Exchange-IIS

Should I also update these apps and does anyone have a process for it that preserves any settings that may have been updated in .conf files or elsewhere.

Thanks
Tom

0 Karma

neelamssantosh
Contributor

Hi Schultet,

Its good to upgrade to latest version but before that make sure that there are no Bugs in the latest version and and all the respective apps are supporting them. Forwarders are always compatible with later version indexers, so you do not need to upgrade them just because you've upgraded the indexers they're sending data to.

Its not necessary to update the apps too. if upgraded,check if the respective logs and fields are getting extracted as required.

In windows the best part is "double click" on the installer and it will get installed :).

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...