Hi @gitau_gm First things first....1) what is the indexer version? Determining forwarder-indexer compatibility is important 2) only few UF's or high number of UF's? if only few, you can manually plan to upgrade. high number of UF's require more manual task or some automatic upgrades can be planned. document for y(our) reference: https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/compatibility-matrix/splunk-products-version-compatibility/compatibility-between-forwarders-and-splunk-enterprise-indexers Forwarder version Splunk Enterprise indexer version 9.2.x 9.3.x 9.4.x 10.0.x 8.1.x E, H, M E, H, M E, H, M E, H, M 8.2.x E, H, M E, H, M E, H, M E, H, M 9.0.x E, H, M E, H, M E, H, M E, H, M 9.1.x E, H, M E, H, M E, H, M E, H, M 9.2.x E, H, M E, H, M E, H, M E, H, M 9.3.x E, H, M E, H, M E, H, M E, H, M 9.4.x E, H, M E, H, M E, H, M E, H, M 10.0.x E, H, M E, H, M E, H, M E, H, M E - Events. This version of forwarder can send event data to the corresponding version of indexer. H - HTTPOUT. This version of forwarder can send event data from Splunk instance to Splunk instance (S2S) over Hypertext Transfer Protocol Secure (HTTPS). M - Metrics. This version of forwarder can send both event data and metrics data to the corresponding version of indexer.
... View more