Enable authentication for Edge Processor package downloads
Reinstall existing Edge Processor instances and enable authenticated package downloads in supported Splunk Enterprise 10.0, 10.2, and 10.4 maintenance releases.
This procedure applies to Splunk Enterprise deployments that run Edge Processors on customer-managed hosts. It does not apply to Splunk Cloud Platform deployments that download packages from the Splunk Cloud package distribution service.
Before you begin, create an inventory of every Edge Processor instance in the deployment and track each instance as you reinstall and verify it.
Make sure that you have the admin role in Splunk Enterprise and administrative access to each instance host.
Supported maintenance releases for Splunk Enterprise 10.0, 10.2, and 10.4 include optional authentication for Edge Processor package downloads. Enabling this setting provides additional security for packages downloaded from Splunk Enterprise to Edge Processor instances.
Package download authentication is inactive by default in these releases. There is no migration deadline, and enabling the setting is optional.
Choose the preparation path
Your preparation depends on whether your deployment has existing Edge Processor instances:
- New deployment: Upgrade Splunk Enterprise to a maintenance release that includes this feature. You can then enable authentication before installing your first Edge Processor instances.
- Existing deployment: Upgrade Splunk Enterprise to a maintenance release that includes this feature, then fully uninstall and reinstall every existing Edge Processor instance before enabling authentication.
Why a full reinstallation is required
Each instance includes an Edge Processor component that starts the instance and downloads required software packages. This component cannot update itself, and older versions cannot authenticate package download requests.
Fully uninstalling and reinstalling an instance using installation commands generated after the Splunk Enterprise upgrade replaces the component with a version that supports authentication. Restarting the instance or waiting for an automatic software update does not complete this preparation.
Plan a rolling reinstallation
An Edge Processor is a logical group that can have one or more instances. Each standalone instance runs on a separate host. If an Edge Processor has multiple instances, you can reinstall them in batches while the remaining instances continue to process data.
Before taking an instance offline:
- Confirm that the remaining instances are Healthy and can process incoming data.
- Confirm how upstream senders or load balancers can stop routing data to an offline instance and fail over to the remaining instances.
- Determine the minimum number of instances required to handle peak traffic. This number is your capacity floor.
Calculate the maximum batch size as follows:
maximum instances offline = total instances - capacity floor
For example, if an Edge Processor has 10 instances and requires 8 instances to handle peak traffic, reinstall no more than 2 instances at a time.
For a single-instance Edge Processor, add a second instance to the same Edge Processor and confirm that it is Healthy and receiving traffic before removing the original instance. If you cannot add temporary capacity, schedule an ingestion interruption and account for the buffering and delivery behavior of each upstream sender.
Review the failover and buffering behavior of each upstream sender. Splunk forwarders must have another available target and sufficient queue capacity. HEC and syslog senders require a resilient client configuration or load balancer. UDP does not guarantee delivery, so provide another collection path or minimize the interruption.
Before you begin
- Upgrade Splunk Enterprise to a supported maintenance release that includes package download authentication.
- Inventory every Edge Processor instance and its host. Maintain a checklist so that you can verify that every existing instance is reinstalled.
- Review the version-specific instructions for setting up, managing, and uninstalling Edge Processors.
Every existing Edge Processor instance is reinstalled and verified before authenticated package downloads are enabled.