Installation

Splunk Cloud Platform universal forwarder credentials package

Eshwar
Engager

Hi Community,

We have configured HF and UF then forwarding  data to Cloud instance. The problem is, we have installed SCP credential pack on HF, not in UF so UF is sending data to HF but UF data is not forwarding by HF to Splunk Cloud but HF internal logs are forwarding to Splunk Cloud. So, Is it necessary to install credential pack on UF to see the UF data in Splunk Cloud through HF or any modifications are required at HF to forward UF data?

Please suggest!

Regards,

Eshwar

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If UFs always forward through HFs then only HFs need the Cloud credentials app.

Are the UFs successfully connecting to the HFs?  Anything in the logs (UF or HF) that might explain what is happening to the UF data?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...