My environment is currently on the Splunk Enterprise 9.2.x track and support will end on Jan 31 2026. I wish to upgrade to either Splunk Enterprise 9.3 or 9.4. Is there any reason to prefer one of these versions (other than support longevity) over the other?
Hi @SplunkNinja
There are a whole load of improvements and new features in 9.4 which you might want to take advantage of.
Also, you might find that some apps on Splunkbase stop supporting older version of Splunk and focus their new features to newer versions.
Unless an essential App you use mandates 9.3 compatibility, I would personally always target the newest stable major/minor version for an upgrade - coming from an older version (9.2.x) to gain the maximum benefit in features, stability, and support lifespan you would be better with 9.4.
Have you considered 10.0? Is there any reason you dont want to move to 9.4/10.0?
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Go through the release notes, compatibility matrix and system requirements. For example at one customer's site I'm for now stuck at 9.2.x due to an underlying OS on which newer releases are not supported.
Also newer versions _might_ be a bit more resource-hungry.