Getting Data In

Running 6.1.1 Searchhead with 6.0 Indexers

jodros
Builder

Aside from the new internal index, are there any issues running a 6.1.1 searchhead with 6.0 indexers? I am trying to test functionality on our searchhead before rolling 6.1.1 to the entire environment.

Thanks

1 Solution

jmheaton
Path Finder

I rolled out 6.1 to a single of our search heads about a week ago. No problems to report here.
Search heads are running 6.1 on one data mount, 6.0 on another mount, with all of our Indexers on 6.0

View solution in original post

0 Karma

jmheaton
Path Finder

I rolled out 6.1 to a single of our search heads about a week ago. No problems to report here.
Search heads are running 6.1 on one data mount, 6.0 on another mount, with all of our Indexers on 6.0

0 Karma

jodros
Builder

Thanks man!

0 Karma

jmheaton
Path Finder

Nothing in the back end logs, nothing in the UI. I dont see anywhere there may be a conflict. Searching works just fine. No conflicts on the indexers themselvs either.

jmheaton
Path Finder

Nothing in the UI, give me a sec and i can check the back end.

0 Karma

jodros
Builder

Did the 6.1 searchhead display any sort of notifications about incompatibility with 6.0 indexers?

0 Karma

jameshgibson
Path Finder

I think your looking for this information. Here's the specific quote:

6.x search heads are compatible with 6.x and 5.x search peers, in a non-clustered environment. The search head must be at the same or higher level than the search peers:

  • A 6.x search head is compatible with a 5.x search peer.
  • A 5.x search head is not compatible with a 6.x search peer.

Search peers here mean your indexers

0 Karma

jodros
Builder

Thank you for your response. I saw this, but was looking for more actual experience in running an environment in this hybrid 6.x way.

Thanks

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...