Installation

Splunk Search Head and Indexer compatibility- Can a 9.4.2 latest version Search Head talk to 9.2.1 indexer?

RAVISHANKAR
Explorer

Hello,

Planning to Upgrade Splunk Enterprise from version 9.2.1 to latest version 9.4.2 - So can a 9.4.2 latest version Search Head talk to 9.2.1 indexer? or we need to upgrade Indexers as well to same version ?

Also Splunk UF 8.0.5 will be able to talk to Indexers ? I read it will be able to talk but only we will not have splunk support for this versions and only we will have P3 support if any issues.

Thanks

Labels (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Here is old answer for upgrade order of nodes in distributed environment. https://community.splunk.com/t5/All-Apps-and-Add-ons/Upgrading-Apps-and-Add-ons-in-distributed-envir...
Quite probably you can this with different order, but then you will gotten some warnings when you are running it before those are in correct versions.

0 Karma

tej57
Builder

In addition to @kiran_panchavat, all the components support backward communication to n-3 Splunk versions in decreasing order of significance in architecture components. First tier is Management nodes like cluster manager, search head cluster deployer. Next would be components like Search Head, Indexer, and then comes the forwarders. 

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@RAVISHANKAR 

Yes, a Splunk Enterprise Search Head running version 9.4.2 can communicate with Indexers running version 9.2.1. But It's recommended to upgrade all components to the same version to ensure full feature compatibility and support.

Yes, UF 8.0.5 can still forward data to Splunk Indexers running 9.2.1 or 9.4.2. However, Splunk no longer provides full support for UF 8.0.x.

Splunk Software Support Policy | Splunk 

About upgrading to 8.0 READ THIS FIRST - Splunk Documentation

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...