Splunk Cloud Platform

Certificate upgrade on universal forwarders

I29851
Explorer

Hello all,

One of the certificates associated with our universal forwarders is due to expire this week. While we have renewed the certificate, we are yet to push it on all universal forwarders. My question is: if we are unable to push new certificate by weekend will the universal forwarders stop logging the data and sharing it with indexes?

Thank you

Labels (3)
0 Karma
1 Solution

SinghK
Builder

But there is a fix, you can create a single cert and push it to all forwarders.

View solution in original post

0 Karma

SinghK
Builder

Yes as the cert is responsible for communication with indexers, so unless cert is a valid cert indexers won't allow it communicate and will not accept logs.

0 Karma

SinghK
Builder

But there is a fix, you can create a single cert and push it to all forwarders.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It's not clear which side of the connection is using certs for authentication - is it only the server or is it mutual tls. In case of mutual tls, you should not use the same crypto material for multiple clients!

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...