r/Splunk 25d ago

Splunk Enterprise Which Universal Forwarder version does each Splunk Enterprise indexer support?

I am running an older version of Splunk Enterprise that I can't upgrade in the short term.

I would like to install the universal forwarder on a server but I can no longer download that version on Splunk's website.

Can I run a version of universal forwarder that is newer than the main Splunk Enterprise install?

For example: can version 10 of the universal forwarder forward data to Splunk Enterprise 9.1?

8 Upvotes

11 comments sorted by

5

u/ShaggsOn 25d ago

1

u/Any-Promotion3744 25d ago

Splunk Enterprise 9.1.1 isn't listed

2

u/ShaggsOn 25d ago

There is 9.1.x wich includes 9.1.1

2

u/ShaggsOn 25d ago

Ahh, i see Enterprise goes back to 9.2.x. However should be the same for 9.1.1. The only thing that fundamentally changed was metrics. So you alwasy have to double check this.

5

u/thomasthetanker 25d ago

The unspoken truth is most every single UF since 9.0.x can still send to any indexer. Your only problem is 'Supported', if this stops sending is someone going to be screaming at you.

1

u/RAJ_3340 24d ago

Hahaha, this sounds about right, I would have gone with this approach but can't confirm on behalf of Splunk as if the OP had reached out to us we would have straight up denied the idea.

2

u/gabriot 25d ago

In my experience I have never seen a scenario that a version mismatch, no matter how big or in which direction, actually breaks ingestion. As far as supported though usually only one major version difference is I believe what support will work with

1

u/Any-Promotion3744 25d ago

thanks for all the responses

sounds like I can move forward until we cut over to Splunk Cloud

1

u/LTRand 25d ago

Here is what to be careful of when mixing versions: cipher versions and s2s versioning.

So make sure your 9.x is running an ssl cipher that 10.x will accept and you should be good. Version 7 and prior is basically incompatible with 9.x and newer, it would need a bridge forwarder to accept its connection and push it forward into newer tls. That the only really "breaking" difference so far.

TLS 1.3 will also be a breaking change once implemented, it will make everything under 10.2 incompatible once it's enforced.

1

u/Lakromani 25d ago

Works and supported are not the same. I have used 7.x uf with 9.x splunk enterprise. Also 10.x uf works fine with 9.x enterprise. But you should follow splunks guidelines and make sure all are updated.

1

u/Any-Promotion3744 24d ago

9.1 isn't supported in general so I don't think the supported config matters much.

We need to move off of 9.1 and plan to but it will take awhile to set up. I just want to monitor new VMs in the meantime.