Deployment Architecture

Not being able to forward data from Windows UF to Splunkcloud

dannyze
Explorer

I am having trouble forwarding data to Splunk cloud from a Windows host. Previously, Linux deployments gave no issues.

Seeing the following error, which I have researched and have not come to any conclusions.

TcpOutputProc - 'sslCertPath' deprecated; use 'clientCert' instead

The cert path itself looks good until further down the splunkd.log where the unix convention of forward slashes causes another error.

ERROR SSLCommon - Can't read certificate file C:\Program Files\SplunkUniversalForwarder\etc/apps/app/default/app_server.pem errno=33558530 error:02001d23562:system library:fopen:No such file or directory

Would like to know ways this has been solved before.
Thank you

Labels (3)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Have you tried getting the latest UF package from your Splunk Cloud stack, or Splunk Administrator? I would start there...

0 Karma

dannyze
Explorer

I am using UF version 8.0.2 and Splunk cloud is version 7.2.9

Noted here, an X in a cell indicates
that this version of forwarder can
send event data to the corresponding
version of indexer.

https://docs.splunk.com/Documentation/Forwarder/8.0.3/Forwarder/Compatibilitybetweenforwardersandind...

According to the docs, it should be compatible

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...