Hello, There is this old system where we want to upgrade splunk to the newest version First we want to upgrade the forwarders on 3 test servers The current version of splunk universal forwarder is 7.0.3.0 We want to rise it to the 9.21 Would that version works for the time being with Splunk Enterprise 7.3.1? I know it would be better first upgrade the enterprise, as best practice is to use indexers with versions that are the same or higher than forwarder versions. (but there is hesitation to upgrade indexers first, as it's used also for data from production) But would it be possible to do forwarders first?
... View more