I am having trouble forwarding data to Splunk cloud from a Windows host. Previously, Linux deployments gave no issues.
Seeing the following error, which I have researched and have not come to any conclusions.
TcpOutputProc - 'sslCertPath' deprecated; use 'clientCert' instead
The cert path itself looks good until further down the splunkd.log where the unix convention of forward slashes causes another error.
ERROR SSLCommon - Can't read certificate file C:\Program Files\SplunkUniversalForwarder\etc/apps/app/default/app_server.pem errno=33558530 error:02001d23562:system library:fopen:No such file or directory
Would like to know ways this has been solved before.
Have you tried getting the latest UF package from your Splunk Cloud stack, or Splunk Administrator? I would start there...
I am using UF version 8.0.2 and Splunk cloud is version 7.2.9
Noted here, an X in a cell indicates
that this version of forwarder can
send event data to the corresponding
version of indexer.
According to the docs, it should be compatible