My organization just purchased splunk enterprise. I'm deploying to a diverse environment and a couple of my end points are MacOS 10.4. I know the current splunk forwarder only supports 10.7 and 10.8. Looking back it looks like splunk 3.4.13 was the last release to support 10.4. Is that what I would download and install for my legacy clients and would then properly forward to my Splunk 6 server?
That should be fine, we have 4.x forwarders sending to 6.0 indexers. I couldn't find any good documentation on compatibility between 3.x and 6.