Installation

Universal forwarder upgradation

uagraw01
Motivator

How can i update my current universal forwarder for splunk ? Please share me all the steps how can i upgrade my version, how to take backeup and all ? Please share for linux and windows both.

Labels (1)
0 Karma

uagraw01
Motivator

Thanks @acharlieh  as i already referred this before.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01 ,

at first you have to define the version to upgrade remembering that the UFs' version must be the same or lower than the Indexers' version.

Splunk doesn't give a tool to upgrade UFs so you can use your Software Distribution tool or someone available on internet (Asnsible, etc...).

If you haven't none, you can use a script that you can find in community answers.

Recently there are two apps to upgrade UFs but I didn't still used:

https://splunkbase.splunk.com/app/5003/

https://splunkbase.splunk.com/app/5004/

Ciao.

Giuseppe

uagraw01
Motivator

@gcusello I want to upgrade this from 6.5.5 to 7.2 ? You have any documented steps rather than Splunk docs. If you have please share it with me.

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01 ,

no I haven't additional documentation, I usually use docs and eventually Community Answers.

If you have to upgrade from 6.5.5 to 7.2.x you shouldn't have a special migration path, but, check if you can upgrade to an higher version so as not to be forced to retry the operation in a short time (we're at 8.0.4 version).

If you have to upgrade from 6.5.5 to 8.x you have to follow an upgrade path (https://docs.splunk.com/Documentation/Splunk/8.0.4/Installation/HowtoupgradeSplunk).

Ciao.

Giuseppe

0 Karma

uagraw01
Motivator

@gcusello Thanks for sharing this.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...