Hello,
I have a plan to upgrade spunk to version 9.* from 8.2, but we are using Splunk Universal Forwarder 7.1.0. Splunk enterprise will be compatible with Splunk Universal Forwarder 7.1.0 or do we have to upgrade Splunk Universal Forwarder to version 9.*?
There is no Splunk solution for UF upgrade managment, however it may be added into Splunk in future.
There is a script below that you can adapt and use, but it comes with no support. You may also consider SCCM for upgrading the UF, or Puppet for example.
7.x is supported, but only just.
Can we upgrade Splunk to version 9.* without upgrading Splunk forwarder?
Yes, for events and metrics.
If you have HEC/HTTPOUT requirements, then you should upgrade the UF tier after the indexers are upgraded.
we have 100 windows machines, how to upgrade UF on all machines?
There is no Splunk solution for UF upgrade managment, however it may be added into Splunk in future.
There is a script below that you can adapt and use, but it comes with no support. You may also consider SCCM for upgrading the UF, or Puppet for example.