Splunk Enterprise

Forwarders version compatibility with Indexer version 8.x

PramodhKumar
Explorer

Hi Folks,

We are having upgrade planned for our clustered environment where we have 400+ forwarders , 14 Int forwarders then Indexers and so on..

As splunk said version 8.x accept connections from forwarders with version 7.x and above.

Notes:
All forwarders running on different versions, 6.x 7.x.
All Intermediate forwarders are on 7.x

So can we proceed with upgrading Indexers to 8.x as literally we receive data feed from Int Forwarders?

Any guidance is highly appreciated

Thanks and Regards,
Pramodh B

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @PramodhKumar,
as you know, the main rule is that Indexers must have a release equal or higher that forwarders, so I think that you have to start from Indexers Upgrade, then Intermediate Forwarders and then the others.

You'll not have problems in Indexers Upgrade, because Intermediate Forwarders are in 7.x release.

The problem could be when you'll upgrade Intermediate Forwarders because there are other Forwarders in 6.x release and they could have problems.
You can approach this problem in two ways:

  1. upgrade 6.x Forwarders twice:
    • upgrade 6.x Forwarders before from 6.x to 7.x (equal to Intermediate Forwarders),
    • then upgrade Intermediate Forwarders to 8.x (the same of Indexers),
    • finally upgrade all the Forwarders to the 8.x version.
  2. have a downtime during upgrade:
    • upgrade Intermediate Forwarders to 8.x ,
    • upgrade 6.x Forwarders to 8.x,
    • upgrade the other Forwarders to 8.x.

The first solution has a minor downtime but requires more work, the second one requires less work but gives you a minor downtime.
If you use a software distribution tool to upgrade Forwarders, the first is the best, if instead you have to manually upgrade Forwarders, maybe, the second is prefereable.

Ciao.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @PramodhKumar,
as you know, the main rule is that Indexers must have a release equal or higher that forwarders, so I think that you have to start from Indexers Upgrade, then Intermediate Forwarders and then the others.

You'll not have problems in Indexers Upgrade, because Intermediate Forwarders are in 7.x release.

The problem could be when you'll upgrade Intermediate Forwarders because there are other Forwarders in 6.x release and they could have problems.
You can approach this problem in two ways:

  1. upgrade 6.x Forwarders twice:
    • upgrade 6.x Forwarders before from 6.x to 7.x (equal to Intermediate Forwarders),
    • then upgrade Intermediate Forwarders to 8.x (the same of Indexers),
    • finally upgrade all the Forwarders to the 8.x version.
  2. have a downtime during upgrade:
    • upgrade Intermediate Forwarders to 8.x ,
    • upgrade 6.x Forwarders to 8.x,
    • upgrade the other Forwarders to 8.x.

The first solution has a minor downtime but requires more work, the second one requires less work but gives you a minor downtime.
If you use a software distribution tool to upgrade Forwarders, the first is the best, if instead you have to manually upgrade Forwarders, maybe, the second is prefereable.

Ciao.
Giuseppe

0 Karma

btshivanand
Path Finder

Hello Sir,this has helped my platform upgrade.We have Intermediate Forwarders which are universal forwarders.Still we need to consider same approach as you mentioned above.

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...