Installation

Upgrade universal forwarder

npandith
Explorer

I am running splunk server(indexer) 4.2.3 on a RHEL machine and appr. 200 universal forwarders(all running 4.2.3) are sending logs to this server. My question is, I want to upgrade my server(indexer) from 4.2.3 to 4.3. So after the indexer upgrade, does the universal forwarders need to be upgraded to 4.3? Please let me know about this. Thanks in Advance!!!

Tags (1)
0 Karma

mikelanghorst
Motivator

It's not required, but there were a couple security fixes in 4.2.5 so you should at least review the change notes for 4.2.5 to see if they apply to you.

ChrisG
Splunk Employee
Splunk Employee

It is not required. "The universal forwarder is both backwards compatible with older Splunk indexers and forward compatible with newer ones. You can forward data to any Splunk indexer that is version 3.4.14 or above" (from the Universal forwarder deployment overview in the Distributed Deployment Manual). If you do want to upgrade your universal forwarders, see the upgrading information in the Installation Manual.

Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...