<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk UF Dmg/PKG Silent Install for Mac in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681625#M18923</link>
    <description>&lt;P&gt;Update, configuration profile works, no notifications are seen from the users perspective and workstation is added into Splunk&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Mar 2024 21:26:15 GMT</pubDate>
    <dc:creator>Knight_Owl</dc:creator>
    <dc:date>2024-03-21T21:26:15Z</dc:date>
    <item>
      <title>Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/657662#M17373</link>
      <description>&lt;P&gt;Hello -&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am trying to script the installation for the Mac Splunk Universal Forwarder package.&amp;nbsp; The package is a disk image (.dmg).&lt;BR /&gt;&lt;BR /&gt;I understand that we can mount the image using hidutil and access the volume to find the .pkg file.&amp;nbsp; The issue comes from where we attempt to run installer -pkg volume/splunkuf.pgk -target /Applications/SplunkUf/ the end user is prompted to answer dialog boxes, which we do not want to occur.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is there a switch to use to install the pkg file silently?&lt;BR /&gt;&lt;BR /&gt;TIA&lt;BR /&gt;JH&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 19:08:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/657662#M17373</guid>
      <dc:creator>jason_hotchkiss</dc:creator>
      <dc:date>2023-09-14T19:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/679432#M18811</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;Did you find a solution for this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 00:52:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/679432#M18811</guid>
      <dc:creator>Knight_Owl</dc:creator>
      <dc:date>2024-03-04T00:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681428#M18909</link>
      <description>&lt;P&gt;I'd love to know as well. I've been banging my head against a wall with this, off and on, for a couple of months now. It's insane to me how impossible it is to find any solutions online (never mind this forum), and Splunk clearly doesn't care to address it.&lt;/P&gt;&lt;P&gt;How exactly are we to do quiet deployments of UF to a fleet of Macs managed by MDM? As it stands, the DMG is out (too much user interaction required, which apparently can't be suppressed), and the .tgz also requires a combination of scripting, permissions changes, possibly creation of a new user, setting environment variables, and moving config files into place.&lt;/P&gt;&lt;P&gt;Can I do this myself? Sure, but why should I have to? Even with the leverage of $GIGANTIC_FEDERAL_AGENCY, Splunk doesn't care to help us.&lt;/P&gt;&lt;P&gt;Godspeed to us all, I guess.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 17:25:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681428#M18909</guid>
      <dc:creator>dkv21210</dc:creator>
      <dc:date>2024-03-20T17:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681433#M18910</link>
      <description>&lt;P&gt;Hi dkv21210,&lt;/P&gt;&lt;P&gt;Are you using JAMF as your MDM?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 17:36:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681433#M18910</guid>
      <dc:creator>Knight_Owl</dc:creator>
      <dc:date>2024-03-20T17:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681435#M18911</link>
      <description>&lt;P&gt;Yes, I am. Previously, with an older version, we just used Jamf Composer watch the file system, then did the manual .pkg installed (user interaction and all), put in our settings files, then had Composer create the package. I really don't want to keep having to do that kind of sloppy install, but it's beginning to look like we may have to.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 17:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681435#M18911</guid>
      <dc:creator>dkv21210</dc:creator>
      <dc:date>2024-03-20T17:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681438#M18912</link>
      <description>&lt;P&gt;So, I was able to get it to silently deploy and it seems to be working as intended&amp;nbsp;&lt;/P&gt;&lt;P&gt;I built the package using Composer, making sure to set the proper R-W-X, Owner, and Group permissions for /Applications/SplunkForwarder&lt;/P&gt;&lt;P&gt;Then added the deploymentclient.conf file within the /Applications/SplunkForwarder/etc/system/local directory before building the package.&lt;/P&gt;&lt;P&gt;Then for my policy I added that package, and for the silent install I added a script which contains:&lt;/P&gt;&lt;P&gt;#!/bin/sh&lt;/P&gt;&lt;P&gt;#Accept Splunk Licenses&lt;/P&gt;&lt;P&gt;/Applications/SplunkForwarder/bin/splunk start --accept-license --auto-ports --no-prompt --answer-yes&lt;/P&gt;&lt;P&gt;# Enable boot start&lt;/P&gt;&lt;P&gt;/Applications/SplunkForwarder/bin/splunk enable boot-start&lt;/P&gt;&lt;P&gt;#Hide the folder&lt;/P&gt;&lt;P&gt;chflags hidden /Applications/SplunkForwarder&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 17:55:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681438#M18912</guid>
      <dc:creator>Knight_Owl</dc:creator>
      <dc:date>2024-03-20T17:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681440#M18913</link>
      <description>&lt;P&gt;Although, I do notice that notifications are still enabled. I created a config profile that mutes Critical Alerts and Notifications for Bundle ID: aplt&lt;/P&gt;&lt;P&gt;Tested it once, seemed to work, but I'd like to test again on a fresh machine to verify.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 17:54:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681440#M18913</guid>
      <dc:creator>Knight_Owl</dc:creator>
      <dc:date>2024-03-20T17:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681443#M18914</link>
      <description>&lt;P&gt;Interesting! Thanks for this; I'll review and give this a try.&lt;/P&gt;&lt;P&gt;One question: &amp;nbsp;Are you creating a Splunk user and changing permissions recursively to splunk:splunk, or are you just leaving it as-is? (To this point, we've been doing the latter, but I'm wondering if creating a dedicated user might be preferable?)&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 18:25:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681443#M18914</guid>
      <dc:creator>dkv21210</dc:creator>
      <dc:date>2024-03-20T18:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681445#M18915</link>
      <description>&lt;P&gt;Leaving it as is.&lt;/P&gt;&lt;P&gt;SplunkForwarder folder and contents within are owned by root and wheel&lt;/P&gt;&lt;P&gt;Applications Folder is owned by root and admin&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 18:43:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681445#M18915</guid>
      <dc:creator>Knight_Owl</dc:creator>
      <dc:date>2024-03-20T18:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681523#M18917</link>
      <description>&lt;P&gt;Sorry, no I did not find a solution, the requirement changed, and we shifted gears.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 11:14:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681523#M18917</guid>
      <dc:creator>jason_hotchkiss</dc:creator>
      <dc:date>2024-03-21T11:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681625#M18923</link>
      <description>&lt;P&gt;Update, configuration profile works, no notifications are seen from the users perspective and workstation is added into Splunk&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 21:26:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/681625#M18923</guid>
      <dc:creator>Knight_Owl</dc:creator>
      <dc:date>2024-03-21T21:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/682313#M19002</link>
      <description>&lt;P&gt;I'm still working on this; I've made some progress on doing the .tar file install and tweaking it, but I'm getting these two alerts (see attached images) whenever I log in to the user account. Have you found a workaround (assuming you've seen this)?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-25 at 1.51.31 PM.png" style="width: 744px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29938iC402E8E83D8FDE92/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-03-25 at 1.51.31 PM.png" alt="Screenshot 2024-03-25 at 1.51.31 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-25 at 1.51.27 PM.png" style="width: 744px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29939i94FEF41E77372384/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-03-25 at 1.51.27 PM.png" alt="Screenshot 2024-03-25 at 1.51.27 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 16:44:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/682313#M19002</guid>
      <dc:creator>dkv21210</dc:creator>
      <dc:date>2024-03-28T16:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/682314#M19003</link>
      <description>&lt;P&gt;Hey DK,&lt;/P&gt;
&lt;P&gt;Build the PKG, then open terminal and run the command&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;sudo xattr -rd com.apple.quarantine /path/to/the.pkg &lt;/LI-CODE&gt;
&lt;P&gt;This will remove the com.apple.quarantine attribute and stop the computer from checking it for malicious software. The -d option deletes the noted attribute and the -r option acts recursively.&lt;/P&gt;
&lt;P&gt;If you would like to check which attributes the .PKG has on it, then run the command:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;xattr -r /path/to/the.pkg&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 17:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/682314#M19003</guid>
      <dc:creator>Knight_Owl</dc:creator>
      <dc:date>2024-03-28T17:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Dmg/PKG Silent Install for Mac</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/682317#M19004</link>
      <description>&lt;P&gt;Perfect! Thanks for the tip.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 17:07:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-UF-Dmg-PKG-Silent-Install-for-Mac/m-p/682317#M19004</guid>
      <dc:creator>dkv21210</dc:creator>
      <dc:date>2024-03-28T17:07:44Z</dc:date>
    </item>
  </channel>
</rss>

