We're looking at possibly upgrading from Splunk 5.0 to the new Splunk 6.0 (which looks awesome). But our environment is quite large. We can upgrade our Indexers, Search Heads, Deployment Servers and License Server fairly quickly, but our forwarders most likely won't be upgraded for some time. Will Splunk 6.0 Indexers still talk to Splunk 5.0 Forwarders? Do we lose any of the new functionality if we keep 5.0 forwarders? Most of the new functionality appears to be with the Indexers and Search head.
Looking at;
http://docs.splunk.com/Documentation/Splunk/6.0/Forwarding/Compatibilitybetweenforwardersandindexers
You will just miss out on two new features, but will work without a problem
old 4.* and 5.* forwarders protocol is compatible with Splunk 6.* indexers.
You can upgrade your key components first :
(search-head, indexers, cluster-master, license-master, deployment-server, eventually heavy forwarders).
And later upgrade the forwarders.
Looking at;
http://docs.splunk.com/Documentation/Splunk/6.0/Forwarding/Compatibilitybetweenforwardersandindexers
You will just miss out on two new features, but will work without a problem