Installation

Splunk Search Head and Indexer compatibility- Can a 9.4.2 latest version Search Head talk to 9.2.1 indexer?

RAVISHANKAR
Loves-to-Learn Lots

Hello,

Planning to Upgrade Splunk Enterprise from version 9.2.1 to latest version 9.4.2 - So can a 9.4.2 latest version Search Head talk to 9.2.1 indexer? or we need to upgrade Indexers as well to same version ?

Also Splunk UF 8.0.5 will be able to talk to Indexers ? I read it will be able to talk but only we will not have splunk support for this versions and only we will have P3 support if any issues.

Thanks

Labels (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Here is old answer for upgrade order of nodes in distributed environment. https://community.splunk.com/t5/All-Apps-and-Add-ons/Upgrading-Apps-and-Add-ons-in-distributed-envir...
Quite probably you can this with different order, but then you will gotten some warnings when you are running it before those are in correct versions.

0 Karma

tej57
Builder

In addition to @kiran_panchavat, all the components support backward communication to n-3 Splunk versions in decreasing order of significance in architecture components. First tier is Management nodes like cluster manager, search head cluster deployer. Next would be components like Search Head, Indexer, and then comes the forwarders. 

0 Karma

kiran_panchavat
Champion

@RAVISHANKAR 

Yes, a Splunk Enterprise Search Head running version 9.4.2 can communicate with Indexers running version 9.2.1. But It's recommended to upgrade all components to the same version to ensure full feature compatibility and support.

Yes, UF 8.0.5 can still forward data to Splunk Indexers running 9.2.1 or 9.4.2. However, Splunk no longer provides full support for UF 8.0.x.

Splunk Software Support Policy | Splunk 

About upgrading to 8.0 READ THIS FIRST - Splunk Documentation

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...