Splunk Enterprise

universal forwarder 6.3.3 release notes? what are the benefits of upgrading from universal forwarder 6.2.1 to 6.33?

sim_tcr
Communicator

Hello,

Is there a place where we can see the universal forwarder 6.3.3 release notes?
I already checked Release Notes But I think thats more for the splunk server.
I am looking for the advantages of upgrading from universal forwarder 6.2.1 to 6.3.3.

Thanks,
Simon Mandy

Tags (1)
0 Karma
1 Solution

ejharts2015
Communicator

Hello,

If splunk suffers from anything its an overabundance of documentation.... everywhere. On each page of the release notes there is a "Changelog" section on the left side of the page and on that a subsection called "Distributed deployment, forwarder and deployment server issues" which should have what you're looking for. Here's what I could find:

Release Notes for the current version: http://docs.splunk.com/Documentation/Splunk/6.3.3/ReleaseNotes/MeetSplunk

Release notes for all version (except the current one): https://www.splunk.com/page/previous_releases/universalforwarder Then select your forwarder OS type.

View solution in original post

ejharts2015
Communicator

Hello,

If splunk suffers from anything its an overabundance of documentation.... everywhere. On each page of the release notes there is a "Changelog" section on the left side of the page and on that a subsection called "Distributed deployment, forwarder and deployment server issues" which should have what you're looking for. Here's what I could find:

Release Notes for the current version: http://docs.splunk.com/Documentation/Splunk/6.3.3/ReleaseNotes/MeetSplunk

Release notes for all version (except the current one): https://www.splunk.com/page/previous_releases/universalforwarder Then select your forwarder OS type.

sloshburch
Splunk Employee
Splunk Employee

Great answer! Also, I believe 6.3 introduced the http event collector and the parallelization. That means the UF can be configured to collect HTTP events. Parallelization means the UF can increase its pipelines (rather than 1) and act as if there were two UF installed thereby increasing performance (while using more available resources).

0 Karma
Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...