Installation

Splunk Enterprise environment use both Windows 2016 and 2019 compatibility

dd_infosec
Engager

We have a client currently running their Splunk Enterprise environment (HF, Indexers and Search Head) in Windows 2016 and they would like to add a new HF in Windows 2019 for HA purposes. Is this supported or is there any compatibility issue?

Kindly share your thoughts. Thanks! 

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @dd_infosec,

leaving out for a moment the fact of having Windows on production systems which is something I don't recommend to any customer, it is a best practice to have the same operating system only on systems belonging to the same cluster (e.g. Indexer Cluster).

So it is not a problem to add an HF with a newer operating system.

The only constraint is the Splunk version which must be equal to or less than that of the Indexers.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @dd_infosec,

leaving out for a moment the fact of having Windows on production systems which is something I don't recommend to any customer, it is a best practice to have the same operating system only on systems belonging to the same cluster (e.g. Indexer Cluster).

So it is not a problem to add an HF with a newer operating system.

The only constraint is the Splunk version which must be equal to or less than that of the Indexers.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...