Getting Data In

Update slpunkclouduf.spl app on Windows Universal Forwarder-  What is the syntax we should use to force the update?

cpkg
Engager

Hi,

Got a message from Splunk that our universal forwarder certificate package will be expiring soon and trying to update the package following their instructions for installing the credentials package (which works on a new/clean install) it returns that we need to use the update argument:

 

 

App "100_XXXX_splunkcloud" already exists; use the "update" argument to install anyway

 

 

This is the syntax used (following Splunk documentation) that returns the message:

 

 

 .\splunk install app ../etc/apps/splunkclouduf.spl -auth xxx:xxxxxxx

 

 

 What is the syntax we should use to force the update? I have tried every which way that I can think of and nothing works. Thanks!

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

You should add 

-update 1

to your

splunk install app

command 

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

You should add 

-update 1

to your

splunk install app

command 

cpkg
Engager

@isoutamothat worked perfectly, thanks!

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...