Hello. In our currently Splunk deployment we have a mix 4.2.* and 4.3.* boxes and are planning an upgrade to Splunk 6. Should the forwarders be upgraded before or after the Indexers, Search Heads, Deploy box.
For example should our path be:
1) Forwarders from 4.2 -> 4.3
2) Indexers, Search Heads, Deploy Server 4.2 -> 4.3
3) Forwarders from 4.3 -> 6.0
4) Indexers, Search Heads, Deploy Server 4.3 -> 6.0
1) Indexers, Search Heads, Deploy Server 4.2 -> 4.3
2) Forwarders from 4.2 -> 4.3
3) Indexers, Search Heads, Deploy Server 4.3 -> 6.0
Here are some doc links you can refer to that can help you map compatibility among forwarders and indexers. Remember, always refer to the documentation for the version you are upgrading to. The links below point to the latest version of the Splunk Enterprise docs, but if you're upgrading to a version that is not the latest, use the version drop-down in the docs to find the instructions for the Splunk Enterprise version you're upgrading to.
These are the specific version compatibility restrictions between forwarders and their receiving indexers:
6.x forwarders (universal/light/heavy) are backwards compatible down to 5.0.x indexers.
6.x indexers are backwards compatible with forwarders down to 5.0.x.