Splunk Enterprise Security

Where can I check Splunk Search Head compatibility with Indexers ?

damode
Motivator

I have Splunk Search Head version 6.5.2 with ES 4.5.2.
I am planning to install Indexers of 7.3.x version. My plan is to eventually upgrade Splunk Search Head as well, however, first I would like to check compatibility between Search Head and Indexer.

I have searched alot but haven't found any documentation for this.
Please advise.

0 Karma
1 Solution

diogofgm
SplunkTrust
SplunkTrust

It's all in the docs. 😉

"While there is some range in compatibility between various Splunk software components, they work best when they are all at a specific version."
Source:
https://docs.splunk.com/Documentation/Splunk/7.3.2/DistSearch/Distsearchsystemrequirements

"The search head must be at the same or a higher level than the search peers."
Source:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Installation/UpgradeyourdistributedSplunkEnterpri...

If your indexer tier is clustered check this:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Indexer/Systemrequirements#Splunk_Enterprise_vers...

Also, don't forget to check compatibility between you SHs and ES.

------------
Hope I was able to help you. If so, some karma would be appreciated.

View solution in original post

0 Karma

diogofgm
SplunkTrust
SplunkTrust

It's all in the docs. 😉

"While there is some range in compatibility between various Splunk software components, they work best when they are all at a specific version."
Source:
https://docs.splunk.com/Documentation/Splunk/7.3.2/DistSearch/Distsearchsystemrequirements

"The search head must be at the same or a higher level than the search peers."
Source:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Installation/UpgradeyourdistributedSplunkEnterpri...

If your indexer tier is clustered check this:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Indexer/Systemrequirements#Splunk_Enterprise_vers...

Also, don't forget to check compatibility between you SHs and ES.

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

damode
Motivator

Thanks I have checked that.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...