Installation

Upgrade universal forwarder

npandith
Explorer

I am running splunk server(indexer) 4.2.3 on a RHEL machine and appr. 200 universal forwarders(all running 4.2.3) are sending logs to this server. My question is, I want to upgrade my server(indexer) from 4.2.3 to 4.3. So after the indexer upgrade, does the universal forwarders need to be upgraded to 4.3? Please let me know about this. Thanks in Advance!!!

Tags (1)
0 Karma

mikelanghorst
Motivator

It's not required, but there were a couple security fixes in 4.2.5 so you should at least review the change notes for 4.2.5 to see if they apply to you.

ChrisG
Splunk Employee
Splunk Employee

It is not required. "The universal forwarder is both backwards compatible with older Splunk indexers and forward compatible with newer ones. You can forward data to any Splunk indexer that is version 3.4.14 or above" (from the Universal forwarder deployment overview in the Distributed Deployment Manual). If you do want to upgrade your universal forwarders, see the upgrading information in the Installation Manual.

Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...