How can i update my current universal forwarder for splunk ? Please share me all the steps how can i upgrade my version, how to take backeup and all ? Please share for linux and windows both.
Splunk's documentation has guides for exactly this:
Thanks @acharlieh as i already referred this before.
Hi @uagraw01 ,
at first you have to define the version to upgrade remembering that the UFs' version must be the same or lower than the Indexers' version.
Splunk doesn't give a tool to upgrade UFs so you can use your Software Distribution tool or someone available on internet (Asnsible, etc...).
If you haven't none, you can use a script that you can find in community answers.
Recently there are two apps to upgrade UFs but I didn't still used:
https://splunkbase.splunk.com/app/5003/
https://splunkbase.splunk.com/app/5004/
Ciao.
Giuseppe
@gcusello I want to upgrade this from 6.5.5 to 7.2 ? You have any documented steps rather than Splunk docs. If you have please share it with me.
Hi @uagraw01 ,
no I haven't additional documentation, I usually use docs and eventually Community Answers.
If you have to upgrade from 6.5.5 to 7.2.x you shouldn't have a special migration path, but, check if you can upgrade to an higher version so as not to be forced to retry the operation in a short time (we're at 8.0.4 version).
If you have to upgrade from 6.5.5 to 8.x you have to follow an upgrade path (https://docs.splunk.com/Documentation/Splunk/8.0.4/Installation/HowtoupgradeSplunk).
Ciao.
Giuseppe
@gcusello Thanks for sharing this.