Installation

Splunk Cloud Platform universal forwarder credentials package

Eshwar
Engager

Hi Community,

We have configured HF and UF then forwarding  data to Cloud instance. The problem is, we have installed SCP credential pack on HF, not in UF so UF is sending data to HF but UF data is not forwarding by HF to Splunk Cloud but HF internal logs are forwarding to Splunk Cloud. So, Is it necessary to install credential pack on UF to see the UF data in Splunk Cloud through HF or any modifications are required at HF to forward UF data?

Please suggest!

Regards,

Eshwar

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If UFs always forward through HFs then only HFs need the Cloud credentials app.

Are the UFs successfully connecting to the HFs?  Anything in the logs (UF or HF) that might explain what is happening to the UF data?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build a No-Code AI Agent at .conf26: Join the AI Agent Buildathon

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...