Reporting

Forwarder compatibility

Twagner79
Explorer

Hello everyone, I hope you all are doing well.   I have been tasked to update Splunk enterprise to the 8.2.1 version and the forwarders to 8.1.4. Does anyone know if this upgrade is going to effect the compatibility for legacy systems? I am worries that RHEL 6 with 7.x version systems will have issues. Just wondering if anyone has had this problem at all. Thank you!

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It's not the RHEL version you should be looking at, but rather the kernel version.  Kernel version compatibility is in the chart referenced above.  RHEL6 should include a supported kernel .

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

We need to know more about your environment.  What are the "legacy systems"?  If they're Splunk then won't they be upgraded to 8.2.1?  What compatibilities are you concerned about?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Twagner79
Explorer

The system is not connected to the internet so it does not get automatically updated. The current systems that are legacy are rhel 6. I am just afraid that upgrading the forwarders on these systems from 7.x to 8.2.1 will make the forwarders not compatible with the OS if that makes sense 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The OS compatibility chart is at https://docs.splunk.com/Documentation/Splunk/8.2.1/Installation/Systemrequirements

---
If this reply helps you, Karma would be appreciated.

Twagner79
Explorer

I appreciate that thank you. Its not quite what I am looking for. The splunk enterprise instance is fine on the server its on, itll upgrade and communicate with the upgraded windows and rhel 7 forwarders fine. It is the RHEL 6 system working with the updated forwarder that I am concerned about, it works fine with the 6x and 7x forwarder version just fine, it is the 8x forwarder that I am worried wont work. Hopefully that is more understandable, I dont mean to be vague  

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not the RHEL version you should be looking at, but rather the kernel version.  Kernel version compatibility is in the chart referenced above.  RHEL6 should include a supported kernel .

---
If this reply helps you, Karma would be appreciated.

Twagner79
Explorer

Thank you again for your help! looks like we are good to go. Happy Splunking 🙂

0 Karma
Get Updates on the Splunk Community!

What’s new on Splunk Lantern in August

This month’s Splunk Lantern update gives you the low-down on all of the articles we’ve published over the past ...

Welcome to the Future of Data Search & Exploration

You have more data coming at you than ever before. Over the next five years, the total amount of digital data ...

This Week's Community Digest - Splunk Community Happenings [8.3.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...