Getting Data In

Upgrade to 7.1.2 from 6.5.1 - Universal Forwarder Upgrade

hemendralodhi
Contributor

Hello Team,

We are planning to upgrade Splunk Enterprise v6.5.1 to v7.1.2. I understand that we need to upgrade or make changes to SSL/TLS config as per http://docs.splunk.com/Documentation/Forwarder/7.1.2/Forwarder/Compatibilitybetweenforwardersandinde...
Current UF Version Deployed and connecting to Heavy Forwarders.
6.2.6
6.3.0
6.3.7
6.4.3
6.5.1
6.5.2
I am confused as in link it says to change the cipher suite on forwarder but when clicked on Known issue list it is not clear where to make the changes.

From Known issue:
SPL-141964 - For splunktcp-ssl - we are not using it
SPL-141961 - This seems to be applicable but it states "Upgrade your older instances to the latest maintenance releases or on your 6.6.x Splunk instances. Add the following stanza to server.conf:"
[sslConfig]
sslVersions = *,-ssl2
sslVersionsForClient = *,-ssl2
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH

Can you advise what changes need to be done? I believe it is SPL-141961 but where this change need to be done IDX/HF/UF?

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

Hi @hemendralodhi,

As you have mentioned that you are not using splunktcp-ssl on Heavy Forwarders for receiving data which means that you are not using SSL communication between UF and Heavy Forwarder. In that case I guess there will not be any problem because I have tested UF 7.0.4 with Indexer 6.5.0 and it is running fine without changing any Ciphers because in my lab I am not using SSL communication between UF and Indexer.

If you are using Deployment Server to distribute configuration to UF in this case, you need to degrade Ciphers in servers.conf sslConfig stanza because UF and Deployment Server talk with each other using SSL so there might be problem with 7.1.X Deployment server and less than 6.6 UF (as far as I am aware Ciphers changed in 6.6)

My recommendation is always upgrade test environment first, test everything and then upgrade production.

I hope this helps.

Thanks,
Harshil

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...