@maheshnc Yes, ideally all your Splunk components—indexers, search heads, deployers, cluster managers, and heavy forwarders—should run the same version and its recommended from Splunk. Refer the below URL for Compatibility matrix: https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/compatibility-matrix/splunk-products-version-compatibility/splunk-products-version-compatibility-matrix For forwarders (both Universal and Heavy), Splunk officially supports a compatibility window where forwarders can be up to two major versions older than your indexers. You can find Splunk’s detailed compatibility guidelines at the official documentation link you referenced, which covers all combinations and exceptional scenarios. refer the below url: https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/compatibility-matrix/splunk-products-version-compatibility/compatibility-between-forwarders-and-splunk-enterprise-indexers High Level upgrade plan -> Pre check Apps/TA compatibility with the new version which you going to upgrade Backup the Splunk etc folder, certs and KV store -> follow the upgrade sequence order -> Post upgrade: verify the cluster health and review the splunkd logs, if you have DMC in your infra go through the console and do the health check
... View more