Installation

Upgrade universal forwarder

npandith
Explorer

I am running splunk server(indexer) 4.2.3 on a RHEL machine and appr. 200 universal forwarders(all running 4.2.3) are sending logs to this server. My question is, I want to upgrade my server(indexer) from 4.2.3 to 4.3. So after the indexer upgrade, does the universal forwarders need to be upgraded to 4.3? Please let me know about this. Thanks in Advance!!!

Tags (1)
0 Karma

mikelanghorst
Motivator

It's not required, but there were a couple security fixes in 4.2.5 so you should at least review the change notes for 4.2.5 to see if they apply to you.

ChrisG
Splunk Employee
Splunk Employee

It is not required. "The universal forwarder is both backwards compatible with older Splunk indexers and forward compatible with newer ones. You can forward data to any Splunk indexer that is version 3.4.14 or above" (from the Universal forwarder deployment overview in the Distributed Deployment Manual). If you do want to upgrade your universal forwarders, see the upgrading information in the Installation Manual.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...