Installation

Newest forwarders compatibility with older version of Splunk Enterprise

nessaner
Explorer

Hello, 
There is this old system where we want to upgrade splunk to the newest version
First we want to upgrade the forwarders on 3 test servers 
The current version of splunk universal forwarder is 7.0.3.0
We want to rise it to the 9.21
Would that version works for the time being with Splunk Enterprise 7.3.1?

I know it would be better first upgrade the enterprise, as best practice is to use indexers with versions that are the same or higher than forwarder versions. (but there is hesitation to upgrade indexers first, as it's used also for data from production)
But would it be possible to do forwarders first? 


Edit: Upgrade was succesfull 😄 

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, it is possible to upgrade forwarders first.  As you've noted, that is contrary to the published procedures and may not work.  Also, Splunk version 7.3.1 is well outdated so there is no guidance about its compatibility with other versions.

This will be an interesting experiment.  Please let us know how it goes.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

nessaner
Explorer

Hi, we decided to create backups and just go for it.
It worked fine! After upgrade everything is indexing without any issues. Also no problem during upgrade from msi.
Thanks for giving us a little courage I guess. We decided to "experiment". For the greater good heh.

richgalloway
SplunkTrust
SplunkTrust

Yes, it is possible to upgrade forwarders first.  As you've noted, that is contrary to the published procedures and may not work.  Also, Splunk version 7.3.1 is well outdated so there is no guidance about its compatibility with other versions.

This will be an interesting experiment.  Please let us know how it goes.

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...