We currently have PingFederate 6.1 but we will be upgrading Pingfederate to7.x then to 8.x. Will the Splunk app for Pingfederate support this upgrade or will the log format change ?
Yes that shouldn't be a problem.
We've added a few parameters in recent releases, but the app should still be able to handle it. Ultimately how you construct the logs is entirely configurable in the log4j.xml / log4j2.xml file packaged in PingFederate.