Installation

what is the supported version of splunk enterprise for RHEL 7.9

krishnaunni
New Member

Dear Team,

I am currently running Splunk Enterprise version 9.1.0.1 on a RHEL 7.9 system. I would like to clarify the following:

What is the supported version of Splunk Enterprise for RHEL 7.9?

Does Splunk Enterprise include Heavy Forwarders (HF) and Deployment Servers (DS) by default, or do these components need to be installed separately?

Given that I currently have Splunk 9.1.0.1 installed on RHEL 7.9, what would be the recommended version of Splunk Enterprise moving forward?

I appreciate your assistance and look forward to your response.

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @krishnaunni 

Given that you are limited to RHEL 7.9 - I would recommend moving to Splunk 9.2.x (9.2.5) which is supported til Jan 31 2026

RHEL 7.9 is supported up to Splunk Enterprise 9.2.x, specifically it is Kernel 3.x which is supported up to 9.2.x however is marked as deprecated - meaning that from future versions it is no longer supported.

"Splunk supports this platform and architecture, but might remove support in a future release"

Kernel 3.x is listed as removed from the 9.3.x build release notes: https://docs.splunk.com/Documentation/Splunk/9.3.0/ReleaseNotes/Deprecatedfeatures#:~:text=in%20this...

Regarding your mention of HF/DS - these are actually the same installation package - Splunk Enterprise is the installation and then the configuration applied to it determines whether it is a HF / DS / SearchHead (SH) etc, with the exception of the Universal Forwarder (UF) which is a smaller package with fewer features available (such as Python environment etc).

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

0 Karma

kiran_panchavat
Champion

@krishnaunni 

What is the supported version of Splunk Enterprise for RHEL 7.9?

For a list of supported operating systems, see

https://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements 

NOTE: Splunk doesn't care what flavor of Linux you use. As long as the kernel is a supported version you'll be fine.

kiran_panchavat_0-1744177368522.png

Does Splunk Enterprise include Heavy Forwarders (HF) and Deployment Servers (DS) by default, or do these components need to be installed separately?

Splunk Enterprise (Full Package) includes all Splunk components except for the Universal Forwarders. Please find the package details below.

Splunk Enterprise:- https://www.splunk.com/en_us/download/splunk-enterprise.html 

Splunk Universal Forwarder:- https://www.splunk.com/en_us/download/universal-forwarder.html 

Splunk Enterprise is a full-featured platform that includes the capabilities for both Heavy Forwarders and Deployment Servers within its installation. These aren’t separate packages you need to install they’re roles you configure within a Splunk Enterprise instance.
 
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

PickleRick
SplunkTrust
SplunkTrust

There are only two installers - the Universal Forwarder and the "full" Splunk Enterprise packages. DS, HF, indexer and so on - these are just server roles which are configured on the "full" installation.

https://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements

https://docs.splunk.com/Documentation/Splunk/latest/Installation/HowtoupgradeSplunk

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...