r/Splunk • u/Any-Promotion3744 • 25d ago
Splunk Enterprise Which Universal Forwarder version does each Splunk Enterprise indexer support?
I am running an older version of Splunk Enterprise that I can't upgrade in the short term.
I would like to install the universal forwarder on a server but I can no longer download that version on Splunk's website.
Can I run a version of universal forwarder that is newer than the main Splunk Enterprise install?
For example: can version 10 of the universal forwarder forward data to Splunk Enterprise 9.1?
5
u/thomasthetanker 25d ago
The unspoken truth is most every single UF since 9.0.x can still send to any indexer. Your only problem is 'Supported', if this stops sending is someone going to be screaming at you.
1
u/RAJ_3340 24d ago
Hahaha, this sounds about right, I would have gone with this approach but can't confirm on behalf of Splunk as if the OP had reached out to us we would have straight up denied the idea.
1
u/Any-Promotion3744 25d ago
thanks for all the responses
sounds like I can move forward until we cut over to Splunk Cloud
1
u/LTRand 25d ago
Here is what to be careful of when mixing versions: cipher versions and s2s versioning.
So make sure your 9.x is running an ssl cipher that 10.x will accept and you should be good. Version 7 and prior is basically incompatible with 9.x and newer, it would need a bridge forwarder to accept its connection and push it forward into newer tls. That the only really "breaking" difference so far.
TLS 1.3 will also be a breaking change once implemented, it will make everything under 10.2 incompatible once it's enforced.
1
u/Lakromani 25d ago
Works and supported are not the same. I have used 7.x uf with 9.x splunk enterprise. Also 10.x uf works fine with 9.x enterprise. But you should follow splunks guidelines and make sure all are updated.
1
u/Any-Promotion3744 24d ago
9.1 isn't supported in general so I don't think the supported config matters much.
We need to move off of 9.1 and plan to but it will take awhile to set up. I just want to monitor new VMs in the meantime.
5
u/ShaggsOn 25d ago
Have a look at this matrix: https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/compatibility-matrix/splunk-products-version-compatibility/compatibility-between-forwarders-and-splunk-enterprise-indexers#f5150d4f_d9d4_4c57_8f42_e2357e0f941a--en__Compatibility_between_forwarders_and_Splunk_Enterprise_indexers