Splunk Enterprise

Forwarder/Indexer compatibility with Intermediate Forwarders

jdmclemore
Path Finder

I've read all the compatibility matrix docs, but I'm not sure how my situation fits into it. Specifically compatibility when sending data through intermediate Heavy Forwarders.

Here's my current environment, and everything is working fine:

UF's (6.3.x - 7.x) ---> Intermediate HF's (7.3.6) ---> Indexer cluster (7.3.6)

I need to point my HF's at newly built 8.x indexers (not upgrading existing indexers - these are new indexers at a new location). Will I have a problem? 

I know that 6.x UFs cant send to 8.x indexers, but am I getting around the problem with a 7.x Intermediate HF? And yes, ideally I would like all UFs to be upgraded, but this situation is temporary.

Thanks!

Labels (1)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi jdmclemore,

Yes you will be fine using the 7.3.x intermediate HF's. But remember that you might have to change some SSL related settings on them if you have those 6.x UF's sending events over S2S using SSL see the docs here https://docs.splunk.com/Documentation/Forwarder/7.3.0/Forwarder/Compatibilitybetweenforwardersandind...

Hope that helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi jdmclemore,

Yes you will be fine using the 7.3.x intermediate HF's. But remember that you might have to change some SSL related settings on them if you have those 6.x UF's sending events over S2S using SSL see the docs here https://docs.splunk.com/Documentation/Forwarder/7.3.0/Forwarder/Compatibilitybetweenforwardersandind...

Hope that helps ...

cheers, MuS

jdmclemore
Path Finder

Thanks!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...