Getting Data In

Update slpunkclouduf.spl app on Windows Universal Forwarder-  What is the syntax we should use to force the update?

cpkg
Engager

Hi,

Got a message from Splunk that our universal forwarder certificate package will be expiring soon and trying to update the package following their instructions for installing the credentials package (which works on a new/clean install) it returns that we need to use the update argument:

 

 

App "100_XXXX_splunkcloud" already exists; use the "update" argument to install anyway

 

 

This is the syntax used (following Splunk documentation) that returns the message:

 

 

 .\splunk install app ../etc/apps/splunkclouduf.spl -auth xxx:xxxxxxx

 

 

 What is the syntax we should use to force the update? I have tried every which way that I can think of and nothing works. Thanks!

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

You should add 

-update 1

to your

splunk install app

command 

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

You should add 

-update 1

to your

splunk install app

command 

cpkg
Engager

@isoutamothat worked perfectly, thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...