Getting Data In

What is the UF upgrade compatibility?

jkrehrer22
Engager

I need to upgrade a several forwarders that are running older versions such as 4.x and 5.x. to 7.x.

Our distributed environment is running at 7.1.4.

Do I need to upgrade the UF to 6.5.2 first? Or, can i upgrade straight to 7.1.4?

0 Karma

sloshburch
Ultra Champion

I recommend you do need to upgrade to 6.6 first to be safe.

While there is no declared issue with UF, this IS called out in the Splunk Enterprise manual.

In fact, for those instances older than 6.0 you may need to upgrade to 5 and then 6 and then 6.6 and then 7.3.

If the UF gets all of it's config from the Deployment Server, you may even consider uninstalling the UF and then installing the latest clean.

0 Karma

pruthvikrishnap
Contributor

It completely depends on the version you are using on your indexers.
Below docs can help.
https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Compatibilitybetweenforwardersandinde...

0 Karma

skalliger
Motivator

You can always install the UF version you want to, as long as it's not newer thant the indexer's version . See here. Installing a newer UF is just an uninstall and reinstall or replacing the files.

Be sure to backup your local files in case of a complete uninstall like mentioned here for Windows or here for *NIX. Remember that the loadbalancing for UFs got optimised, take a look here in case you want to change a few things: configure loadbalancing.

Skalli

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...