Hello, Please find the answers below. 1) Prerequisites and requirements for upgrading Splunk Universal Forwarder Before upgrading the Splunk Universal Forwarder, it is recommended to verify the following: Operating system compatibility: Verify that the operating system is supported by the target Universal Forwarder version. Supported upgrade path: Review the supported upgrade path and any upgrade considerations for the target version. App/Add-on compatibility: Verify the compatibility of any installed apps or add-ons with the target version by reviewing the respective Splunkbase pages. Disk space: Ensure sufficient disk space is available for the upgrade. Release notes: Review the release notes and known issues for the target version before proceeding. Therefore, the understanding that the prerequisites primarily involve verifying operating system compatibility and installed app/add-on compatibility is correct. However, the supported upgrade path, available disk space, release notes, and any version-specific upgrade considerations should also be reviewed. References: About upgrading to 10.2 – READ THIS FIRST: https://help.splunk.com/en/splunk-enterprise/administer/install-and-upgrade/10.2/upgrade-or-migrate-splunk-enterprise/about-upgrading-to-10.2-read-this-first System requirements: https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.2/plan-your-splunk-enterprise-installation/system-requirements-for-use-of-splunk-enterprise-on-premises Upgrade the Universal Forwarder: https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/universal-forwarder-manual/10.2/upgrade-or-uninstall-the-universal-forwarder/upgrade-the-universal-forwarder 2) Recommended backup and rollback procedures Before upgrading the Universal Forwarder, it is recommended to back up the existing installation configuration, particularly the $SPLUNK_HOME/etc directory. This directory contains important configuration files such as inputs.conf, outputs.conf, deploymentclient.conf, server.conf, and any custom apps or local configurations. If the Universal Forwarder is managed by a Deployment Server, it is also recommended to ensure that the relevant deployment apps are backed up on the Deployment Server. If rollback is required, the general approach is: Stop the Universal Forwarder service. Reinstall the previous Universal Forwarder version. Restore the backed-up configuration files, if necessary. Start the Universal Forwarder service. Verify that data forwarding resumes successfully. Splunk normally preserves the existing configuration during an upgrade. However, maintaining a backup before the upgrade is recommended to support recovery if any issue occurs. Reference: Back up configuration information: https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/administer-splunk-enterprise-with-configuration-files/back-up-configuration-information
... View more