Splunk Enterprise

universal forwarder 6.3.3 release notes? what are the benefits of upgrading from universal forwarder 6.2.1 to 6.33?

sim_tcr
Communicator

Hello,

Is there a place where we can see the universal forwarder 6.3.3 release notes?
I already checked Release Notes But I think thats more for the splunk server.
I am looking for the advantages of upgrading from universal forwarder 6.2.1 to 6.3.3.

Thanks,
Simon Mandy

Tags (1)
0 Karma
1 Solution

ejharts2015
Communicator

Hello,

If splunk suffers from anything its an overabundance of documentation.... everywhere. On each page of the release notes there is a "Changelog" section on the left side of the page and on that a subsection called "Distributed deployment, forwarder and deployment server issues" which should have what you're looking for. Here's what I could find:

Release Notes for the current version: http://docs.splunk.com/Documentation/Splunk/6.3.3/ReleaseNotes/MeetSplunk

Release notes for all version (except the current one): https://www.splunk.com/page/previous_releases/universalforwarder Then select your forwarder OS type.

View solution in original post

ejharts2015
Communicator

Hello,

If splunk suffers from anything its an overabundance of documentation.... everywhere. On each page of the release notes there is a "Changelog" section on the left side of the page and on that a subsection called "Distributed deployment, forwarder and deployment server issues" which should have what you're looking for. Here's what I could find:

Release Notes for the current version: http://docs.splunk.com/Documentation/Splunk/6.3.3/ReleaseNotes/MeetSplunk

Release notes for all version (except the current one): https://www.splunk.com/page/previous_releases/universalforwarder Then select your forwarder OS type.

sloshburch
Splunk Employee
Splunk Employee

Great answer! Also, I believe 6.3 introduced the http event collector and the parallelization. That means the UF can be configured to collect HTTP events. Parallelization means the UF can increase its pipelines (rather than 1) and act as if there were two UF installed thereby increasing performance (while using more available resources).

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...