Here are some doc links you can refer to that can help you map compatibility among forwarders and indexers. Remember, always refer to the documentation for the version you are upgrading to. The links below point to the latest version of the Splunk Enterprise docs, but if you're upgrading to a version that is not the latest, use the version drop-down in the docs to find the instructions for the Splunk Enterprise version you're upgrading to.
Compatibility between forwarders and Splunk Enterprise indexers
Distributed search: Compatibility between search heads and search peers
To determine whether you need to do a two-step upgrade to skip versions, see Upgrade paths to version (latest).
A detail to pay attention to is the compatibility of cipher suites among the different versions. See the documentation for instructions about how to Configure secure communications between Splunk instances with updated cipher suite and message authentication code.
These links and more, along with a roadmap overview of the upgrade process and order of operations, are in the post What's the order of operations for upgrading Splunk Enterprise?
... View more