Getting Data In

Can a heavy forwarder be higher version than indexers?

a_naoum
Path Finder

Hi,

I don't think that I found this kind of question before but in general I know the case for different versions between the indexers-search heads but my question is:
Can a heavy forwarder be higher version than indexers?

0 Karma

harsmarvania57
Ultra Champion

I would like to point out that question is for Heavy Forwarder, however Forwarder compatibility link which is provided in answer is for Comparability between Universal Forwarder and Splunk Indexer.

Heavy Forwarder is same as Splunk Indexer (Search Peer), only difference is Heavy Forwarder do not store data in general and pass parsed data to Indexer so based on my knowledge this is correct link from doc https://docs.splunk.com/Documentation/Splunk/7.2.6/Indexer/Systemrequirements#Compatibility_between_... for compatibility between Heavy Forwarder and Indexer, please correct me if I am wrong.

sanjeev543
Communicator

Technically yes, but there are limitations on what kind of Data forwarder can send, if you maintain higher version of HF.
Please refer to the below compatibility matrix.
https://docs.splunk.com/Documentation/Forwarder/7.2.6/Forwarder/Compatibilitybetweenforwardersandind...

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hi @a_naoum,

Indexer should be in higher version than the forwarder, please visit Forwarder Compatibility.

kamlesh_vaghela
SplunkTrust
SplunkTrust

@a_naoum

Check "Determine forwarder-indexer compatibility" section in below link.

https://docs.splunk.com/Documentation/Forwarder/7.2.6/Forwarder/Compatibilitybetweenforwardersandind...

a_naoum
Path Finder

As others mention is it applicable for HF?

pellegrini
Path Finder

Yes it is applicable for standard HF functionality as well. At least according to Docs. Some special cases where the HF is configured differently then just forward events it might be different.

https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Officially this is not a supported combination. Indexer should/must be at higher level to fulfil Splunk requirements and get support if needed. Best practices is ensure that receiver is at least same level than sender.

Fortunately in most cases HFs and UFs can be higher level than IDX is. Normally this work well but time by time (when newer versions has some new features) this will cause some issues and even those didn't work together without additional changes on configuration.

r. Ismo

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...