Install and configure the Splunk Cloud Platform universal forwarder credentials package
To enable your forwarders to send data to Splunk Cloud Platform, download the universal forwarder credentials file. This file contains a custom certificate for your Splunk Cloud Platform deployment.
Download the forwarder credentials
- From your Splunk Cloud Platform instance, go to Apps > Universal Forwarder.
- Click Download Universal Forwarder Credentials.
- Note the location where the credentials file was downloaded. The credentials file is named
- Copy the file to your /tmp folder.
Install the file onto your forwarders using one of the two installation options described in this topic. Apply these credentials to forwarders of any type that you need to connect to your Splunk Cloud Platform instance.
Install the forwarder credentials on individual forwarders
- Install the following app by entering the following command:
/opt/splunkforwarder/bin/splunk install app /tmp/splunkclouduf.spl.
- When you are prompted for a user name and password, enter the user name and password for the Universal Forwarder. The following message displays if the installation is successful:
App '/tmp/splunkclouduf.spl' installed.
- Restart the forwarder to enable the changes by entering the following command.
Install the forwarder credentials on a deployment server
- Use file management tools to move the
splunkclouduf.splfile to the
$SPLUNK_HOME/etc/deployment-apps/directory on the deployment server.
- Open a shell or command prompt.
- Unpack the credentials package by running the following command: .
tar xvf splunkclouduf.spl
- Navigate to the
/binsubdirectory of the deployment server.
- Install the credentials package by running the following command: where
splunk install app <full path to splunkclouduf.spl> -auth <username>:<password>
<full path to splunkclouduf.spl>is the path to the directory where the
splunkclouduf.splfile is located and
<username>:<password>are the username and password of an existing admin account on the universal forwarder.
- Restart the deployment server by running the following command:
How to forward data to Splunk Cloud Platform
How to forward data to Splunk Enterprise
This documentation applies to the following versions of Splunk® Universal Forwarder: 126.96.36.199, 8.2.4