Getting Data In

Can a heavy forwarder be higher version than indexers?

a_naoum
Path Finder

Hi,

I don't think that I found this kind of question before but in general I know the case for different versions between the indexers-search heads but my question is:
Can a heavy forwarder be higher version than indexers?

0 Karma

harsmarvania57
Ultra Champion

I would like to point out that question is for Heavy Forwarder, however Forwarder compatibility link which is provided in answer is for Comparability between Universal Forwarder and Splunk Indexer.

Heavy Forwarder is same as Splunk Indexer (Search Peer), only difference is Heavy Forwarder do not store data in general and pass parsed data to Indexer so based on my knowledge this is correct link from doc https://docs.splunk.com/Documentation/Splunk/7.2.6/Indexer/Systemrequirements#Compatibility_between_... for compatibility between Heavy Forwarder and Indexer, please correct me if I am wrong.

sanjeev543
Communicator

Technically yes, but there are limitations on what kind of Data forwarder can send, if you maintain higher version of HF.
Please refer to the below compatibility matrix.
https://docs.splunk.com/Documentation/Forwarder/7.2.6/Forwarder/Compatibilitybetweenforwardersandind...

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hi @a_naoum,

Indexer should be in higher version than the forwarder, please visit Forwarder Compatibility.

kamlesh_vaghela
SplunkTrust
SplunkTrust

@a_naoum

Check "Determine forwarder-indexer compatibility" section in below link.

https://docs.splunk.com/Documentation/Forwarder/7.2.6/Forwarder/Compatibilitybetweenforwardersandind...

a_naoum
Path Finder

As others mention is it applicable for HF?

pellegrini
Path Finder

Yes it is applicable for standard HF functionality as well. At least according to Docs. Some special cases where the HF is configured differently then just forward events it might be different.

https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/Compatibilitybetweenforwar...

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Officially this is not a supported combination. Indexer should/must be at higher level to fulfil Splunk requirements and get support if needed. Best practices is ensure that receiver is at least same level than sender.

Fortunately in most cases HFs and UFs can be higher level than IDX is. Normally this work well but time by time (when newer versions has some new features) this will cause some issues and even those didn't work together without additional changes on configuration.

r. Ismo

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...