Splunk 版本有的有logj4的漏洞,有的splunk 开case 都不支持,所以splunk 升级变成了常见的场景:
Suggested order for the upgrade is:
1. Search heads, deployers, Deployment servers
2. Cluster master
3. Indexers
4. Forwarders.
To see if you should upgrade the forwarders before or after Indexers and rest of the components, I'd advise you to go through the compatibility matrix. In some versions, a higher version of HF/UF won't send metrix data to Indexers. That won't happen in your case (since you're upgrading from 8 to 8.2, where forwarders and Indexers are compatible with each other for both event and metrics data), so you're free to upgrade forwarders before everything or at the end.