Getting Data In

Universal Forwarder Credentials

JMonk
New Member

What is the correct way to upgrade the credentials on a universal forwarder. Ours will expire soon, When I run splunk install app -update, getting the following error:
Cannot perform action "POST" without a target name to act on.

0 Karma

woodcock
Esteemed Legend

There is nothing in Splunk that would case your Universal Forwarder credentials to expire. Are you talking about your SSL certificate?

0 Karma

ivanreis
Builder

please try this command to change the local user on universal forwarder for admin user.
linux command : /opt/splunkforwarder/bin/splunk edit user admin -password -auth admin:

windows command : c:\bin\splunk edit admin -password -auth admin:
depends on the number of clients you have to apply this change I recommend to use a script or other tools to deploy new configuration to you environment.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What credentials are you trying to change? What is the exact command you're running?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...

Enterprise Security Content Update (ESCU) | New Releases

In October, the Splunk Threat Research Team had one release of new security content via the Enterprise ...