Getting Data In

Update slpunkclouduf.spl app on Windows Universal Forwarder-  What is the syntax we should use to force the update?

cpkg
Engager

Hi,

Got a message from Splunk that our universal forwarder certificate package will be expiring soon and trying to update the package following their instructions for installing the credentials package (which works on a new/clean install) it returns that we need to use the update argument:

 

 

App "100_XXXX_splunkcloud" already exists; use the "update" argument to install anyway

 

 

This is the syntax used (following Splunk documentation) that returns the message:

 

 

 .\splunk install app ../etc/apps/splunkclouduf.spl -auth xxx:xxxxxxx

 

 

 What is the syntax we should use to force the update? I have tried every which way that I can think of and nothing works. Thanks!

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

You should add 

-update 1

to your

splunk install app

command 

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

You should add 

-update 1

to your

splunk install app

command 

cpkg
Engager

@isoutamothat worked perfectly, thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...