Splunk Cloud Platform

What do I do about this message: Splunk Cloud upgrade Universal Forwarder certificate package?

splunkcol
Builder

Hello,

"The ingestion certificates on xxxx Splunk Cloud environment xxx Universal Forwarder certificate package, will be expiring on x/xx/2022. In order to ensure that ingestion is not disrupted, we have rolled out an updated Universal Forwarder (UF) package to your customer’s Splunk Cloud Platform stack. The operational contacts have been informed of this information via xxxx. They will need to install this updated package on all forwarders connecting to their Splunk Cloud Stack as soon as possible. We are asking you to please reach out to your customer and verify they are aware that they are responsible for rolling out this package and should do so immediately."

I have received a message from splunk and I would like you to please confirm if what I must do is related to this link https://docs.splunk.com/Documentation/Forwarder/9.0.1/Forwarder/ConfigSCUFCredentials?ref=hk#Howtofo...

splunkcol_0-1661352998628.png

 

 

 

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, those are the instructions for individual Linux forwarders.  If you use a deployment server then follow the relevant instructions in the same document.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Yes, those are the instructions for individual Linux forwarders.  If you use a deployment server then follow the relevant instructions in the same document.

---
If this reply helps you, Karma would be appreciated.

splunkcol
Builder

It is a heavy forwarder only that points to Splunk Cloud, that is to say that I only have to:

1. Download the splunkclouduf.spl file again from splunk cloud

2. SSH into the Heavy forwarder and put the splunkclouduf.spl file in a temporary folder

3. Enter the splunk bin folder and run this command

/opt/splunkforwarder/bin/splunk install app /tmp/splunkclouduf.spl

4. enter the credentials of the HV and that's it?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, that's it.

---
If this reply helps you, Karma would be appreciated.

splunkcol
Builder

Thank you very much for the help

Sorry for the bad translation I used

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...