Dear Team,
I am currently running Splunk Enterprise version 9.1.0.1 on a RHEL 7.9 system. I would like to clarify the following:
What is the supported version of Splunk Enterprise for RHEL 7.9?
Does Splunk Enterprise include Heavy Forwarders (HF) and Deployment Servers (DS) by default, or do these components need to be installed separately?
Given that I currently have Splunk 9.1.0.1 installed on RHEL 7.9, what would be the recommended version of Splunk Enterprise moving forward?
I appreciate your assistance and look forward to your response.
Hi @krishnaunni
Given that you are limited to RHEL 7.9 - I would recommend moving to Splunk 9.2.x (9.2.5) which is supported til Jan 31 2026
RHEL 7.9 is supported up to Splunk Enterprise 9.2.x, specifically it is Kernel 3.x which is supported up to 9.2.x however is marked as deprecated - meaning that from future versions it is no longer supported.
"Splunk supports this platform and architecture, but might remove support in a future release"
Kernel 3.x is listed as removed from the 9.3.x build release notes: https://docs.splunk.com/Documentation/Splunk/9.3.0/ReleaseNotes/Deprecatedfeatures#:~:text=in%20this...
Regarding your mention of HF/DS - these are actually the same installation package - Splunk Enterprise is the installation and then the configuration applied to it determines whether it is a HF / DS / SearchHead (SH) etc, with the exception of the Universal Forwarder (UF) which is a smaller package with fewer features available (such as Python environment etc).
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
What is the supported version of Splunk Enterprise for RHEL 7.9?
For a list of supported operating systems, see
NOTE: Splunk doesn't care what flavor of Linux you use. As long as the kernel is a supported version you'll be fine.
Does Splunk Enterprise include Heavy Forwarders (HF) and Deployment Servers (DS) by default, or do these components need to be installed separately?
Splunk Enterprise (Full Package) includes all Splunk components except for the Universal Forwarders. Please find the package details below.
Splunk Enterprise:- https://www.splunk.com/en_us/download/splunk-enterprise.html
Splunk Universal Forwarder:- https://www.splunk.com/en_us/download/universal-forwarder.html
There are only two installers - the Universal Forwarder and the "full" Splunk Enterprise packages. DS, HF, indexer and so on - these are just server roles which are configured on the "full" installation.