Splunk Cloud Platform

Upgrade Heavy Forwarder from 9.0.x to 9.2.x

petsafe
Loves-to-Learn

I have a Splunk cloud instance that receives log from Linux server that has a Splunk Heavy Forwarder on it.

I am trying to update the Forwarder to 9.3.x, but found online I should step to 9.2.x first. It appears on the server that it's updated, and running the Splunk 9.2.0 as expected. I am also seeing metric.log files being shown on my cloud instance. But none of the other logs I have pushing from this server are showing up.

When I check the Splunk app CMC, it appears that the update has taken and is now showing in compliance.

I am not sure what I am doing wrong, or what logs you might need to help further figure out where the issue is. I only have about 6 months of Splunk experience so forgive me if this is a silly question.

Labels (3)
0 Karma

PaulPanther
Motivator

@petsafe Please describe the steps that you executed for the upgrade. 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...