I would like to upgrade our Splunk 5 Servers to version 6.
But for some reasons, I don't want to upgrade the indexer servers at this time.
So I think I would upgrade the Search Head Server to Splunk 6 first, take advantage of new features ,
and remain the indexer servers as version 5.
I have tested this solution in my lab and looked just O.K. , but I was wondering if there are any side-effects?
Running Splunk 6 search heads against Splunk 5 indexers is supported, see http://docs.splunk.com/Documentation/Splunk/6.0.3/DistSearch/Versioncompatibility for a few small caveats.