<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: bash script , automating splunkforwarder installation. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516926#M3174</link>
    <description>&lt;P&gt;Hope you will manage deployment clients(where uf is installed) with deployment server. If yes, you don’t require to set the password at all.&lt;/P&gt;</description>
    <pubDate>Sun, 30 Aug 2020 17:54:47 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-08-30T17:54:47Z</dc:date>
    <item>
      <title>Has anyone written a bash script to install splunkforwarder on a linux server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516336#M3147</link>
      <description>&lt;P&gt;has anyone written a bash script to install splunkforwarder on a linux server? or is it impossible due to having to enter admin and password and also having to use different users while installing ?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 15:44:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516336#M3147</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2022-06-21T15:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516340#M3148</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;there is example on Splunk’s docs&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/Installanixuniversalforwarderremotelywithastaticconfiguration" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/Installanixuniversalforwarderremotelywithastaticconfiguration&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that you could found several ansible playbooks for doing this which could be more manageable? Personally I prefer ansible over shell scrips for this kind of stuff.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 18:10:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516340#M3148</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-26T18:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516348#M3149</link>
      <description>See &lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/Installanixuniversalforwarderremotelywithastaticconfiguration" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/Installanixuniversalforwarderremotelywithastaticconfiguration&lt;/A&gt;</description>
      <pubDate>Wed, 26 Aug 2020 18:33:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516348#M3149</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-26T18:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516351#M3150</link>
      <description>&lt;P&gt;It’s not impossible as you don’t require to set admin password while installing. You can automate this one completely.&lt;/P&gt;&lt;P&gt;I will share script soon.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 18:50:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516351#M3150</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-26T18:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516457#M3153</link>
      <description>&lt;P&gt;Thank you, cant wait to see it&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 08:00:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516457#M3153</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-08-27T08:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516462#M3154</link>
      <description>&lt;P&gt;With sensible you could also set admin passwords when you installing it.&lt;/P&gt;&lt;P&gt;Here is Splunk's own ansible which they are actively updated.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://github.com/splunk/splunk-ansible/tree/master" target="_blank"&gt;https://github.com/splunk/splunk-ansible/tree/master&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;And some other playbooks:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://github.com/AustinCloudGuru/ansible-role-splunk-forwarder" target="_blank"&gt;https://github.com/AustinCloudGuru/ansible-role-splunk-forwarder&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.linuxsysadmins.com/splunk-forwarder-installation-using-ansible/" target="_blank"&gt;https://www.linuxsysadmins.com/splunk-forwarder-installation-using-ansible/&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 08:14:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516462#M3154</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-27T08:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516520#M3156</link>
      <description>&lt;P&gt;This is applicable for version 7.2.2 later.&lt;/P&gt;&lt;P&gt;you should run below commands with sudo user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;useradd splunk
tar splunkbinary.gz -C /opt
chown -R splunk:splunk /opt/splunkforwarder
/opt/splunkforwarderk/bin/splunk enable boot-start -systemd-managed 0 -user splunk --no-prompt --accept-license
sudo -u splunk /opt/splunkforwarderk/bin/splunk start&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 14:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516520#M3156</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-27T14:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516923#M3173</link>
      <description>&lt;P&gt;and when do i add admin and password?&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2020 16:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516923#M3173</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-08-30T16:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516926#M3174</link>
      <description>&lt;P&gt;Hope you will manage deployment clients(where uf is installed) with deployment server. If yes, you don’t require to set the password at all.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2020 17:54:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/516926#M3174</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-30T17:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/517012#M3180</link>
      <description>&lt;P&gt;okay, so when I add a log to monitor it wont require a password&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 12:21:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/517012#M3180</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-08-31T12:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/517016#M3181</link>
      <description>&lt;P&gt;that's why I have asked you, I hope you manage this client from Deployment server.&lt;/P&gt;&lt;P&gt;It will prompt for password if you add from CLI using splunk command.&lt;/P&gt;&lt;P&gt;you can update inputs.conf&amp;nbsp; to avoid prompting for password.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 12:43:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/517016#M3181</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-31T12:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/517020#M3182</link>
      <description>&lt;P&gt;Yes I'm using CLI&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 13:09:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/517020#M3182</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-08-31T13:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/542883#M5209</link>
      <description>&lt;P&gt;See also: &lt;A href="https://github.com/splunk/ansible-role-for-splunk" target="_self"&gt;Splunk's official Ansible role for VMs and bare metal&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 18:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/542883#M5209</guid>
      <dc:creator>masonmorales</dc:creator>
      <dc:date>2021-03-08T18:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602200#M12878</link>
      <description>&lt;P&gt;hi team,&lt;/P&gt;&lt;P&gt;Can you please provide shell script&amp;nbsp; to install forwarder into server. Basically i have a task to automate same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 07:25:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602200#M12878</guid>
      <dc:creator>nikhilmfwd</dc:creator>
      <dc:date>2022-06-17T07:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602280#M12890</link>
      <description>&lt;P&gt;Since this thread is 2 years old with an accepted solution, you should post a new question.&lt;/P&gt;&lt;P&gt;That said, have you tried this one?&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Simple-installation-script-for-Universal-Forwarder/m-p/21517" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Simple-installation-script-for-Universal-Forwarder/m-p/21517&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 19:13:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602280#M12890</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-06-17T19:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602462#M12904</link>
      <description>&lt;P&gt;This is an old version of a script I use to install splunk forwarder on Linux (ubuntu) servers and connect up to a splunk enterprise instance and deployment server. In case this may be useful to anyone who comes across this thread in the future&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;#!/bin/bash
set -o errexit
# This will delete the installation of splunk forwarder if there already is one installed. allows you to run script to reinstall
sudo rm -f /opt/splunkforwarder

# Edit this section to get the most recent up to date wget command for downloading splunk forwarder
sudo wget -O splunkforwarder-8.2.0-e053ef3c985f-Linux-x86_64.tgz
'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&amp;amp;platform=linux&amp;amp;version=8.2.0&amp;amp;product=universalforwarder&amp;amp;filename=spl$
sudo tar xvzf splunkforwarder-8.2.0-e053ef3c985f-Linux-x86_64.tgz -C /opt
cd /opt/splunkforwarder/bin

# default username is admin
# generates random password for admin account
sudo ./splunk start --accept-license --no-prompt --gen-and-print-passwd
#enables start on boot
sudo ./splunk enable boot-start

#Adds the instance of where you are going to be forwarding your logs
cd /opt/splunkforwarder/etc/system/local
sudo touch outputs.conf
echo "" | sudo tee -a /opt/splunkforwarder/etc/system/local/outputs.conf
echo "[tcpout]" | sudo tee -a /opt/splunkforwarder/etc/system/local/outputs.conf
echo "defaultGroup = default-autolb-group" | sudo tee -a /opt/splunkforwarder/etc/system/local/outputs.conf
echo "" | sudo tee -a /opt/splunkforwarder/etc/system/local/outputs.conf
echo "[tcpout:default-autolb-group" | sudo tee -a /opt/splunkforwarder/etc/system/local/outputs.conf
echo "disabled = false" | sudo tee -a /opt/splunkforwarder/etc/system/local/outputs.conf
echo "server = NAME_OF_YOUR_SPLUNK_SERVER:9997" | sudo tee -a /opt/splunkforwarder/etc/system/local/outputs.conf
echo "" | sudo tee -a /opt/splunkforwarder/etc/system/local/outputs.conf
echo "[tcpout-server://NAME_OF_YOUR_SPLUNK_SERVER:9997]" | sudo tee -a /opt/splunkforwarder/etc/system/local/outputs.conf

#adds the monitoring of var/log/syslog (relatively important for monitoring linux (ubuntu) servers. optional however and can be configured
from a deployment server)
sudo touch inputs.conf
echo "[monitor://var/log/syslog]" | sudo tee -a /opt/splunkforwarder/etc/system/local/inputs.conf
echo "disabled = 0" | sudo tee -a /opt/splunkforwarder/etc/system/local/inputs.conf

#adds the deployment server for managing the newly created instance (optional but defnitely should use a deployment server)
sudo touch deploymentclient.conf
echo "[deployment-client]" | sudo tee -a /opt/splunkforwarder/etc/system/local/deploymentclient.conf
echo "[target-broker:deploymentServer]" | sudo tee -a /opt/splunkforwarder/etc/system/local/deploymentclient.conf
echo "targetUri = NAME_OF_DEPLOYMENT_SERVER:8089" | sudo tee -a /opt/splunkforwarder/etc/system/local/deploymentclient.conf

#reboots splunk to save changes
cd /opt/splunkforwarder/bin
sudo ./splunk restart&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 18:45:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602462#M12904</guid>
      <dc:creator>pc1</dc:creator>
      <dc:date>2022-06-20T18:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602471#M12905</link>
      <description>&lt;P&gt;Let me point out some flaws with your script.&lt;/P&gt;&lt;P&gt;1) Unconditional removal of /opt/splunkforwarder can be a bit hasty. Especially if you're using TLS and have crypto material stores somewhere in $SPLUNK_HOME&lt;/P&gt;&lt;P&gt;2) You're doing way too many things with sudo. Sudo should be used only if it's absolutely necessary. wget with elevated privileges? What for?&lt;/P&gt;&lt;P&gt;3) You're wgetting the installation archive into current directory. It'd be more elegant to create a temporary directory.&lt;/P&gt;&lt;P&gt;4) Instead of multiple echos you can simply do one cat with here-document.&lt;/P&gt;&lt;P&gt;5)&amp;nbsp; You're leaving the installation archive behind.&lt;/P&gt;&lt;P&gt;6) The script could be parametrised.&lt;/P&gt;&lt;P&gt;7) You're happily ignoring randomly generated admin credentials. You might need them later.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; You can use splunk commands to modify configuration instead of creating the files by hand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 19:31:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602471#M12905</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-06-20T19:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602476#M12906</link>
      <description>&lt;P&gt;I said it was old. &lt;span class="lia-unicode-emoji" title=":grinning_squinting_face:"&gt;😆&lt;/span&gt;If it works it works&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;1) Idk what you mean by crypto materials. bitcoin?&lt;BR /&gt;It should probably have a sudo ./splunk stop command before deleting the directory but idk what else you would want&lt;BR /&gt;&lt;BR /&gt;2) wget doesn't need sudo? idk&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;3) so essentially cd /opt &amp;amp;&amp;amp; wget install splunk &amp;amp;&amp;amp; then delete the install file ?&lt;BR /&gt;&lt;BR /&gt;4) yeah ur right&lt;BR /&gt;&lt;BR /&gt;5) i guess it would be better practice to do that. i was just copy and pasting from my notes to try and help&lt;BR /&gt;&lt;BR /&gt;6) it could but i just wrote the variables in caps to be changed since the point of my script when i wrote it is to have Zero user interaction&lt;BR /&gt;&lt;BR /&gt;7) again I want zero user interaction so randomly generating them into the void works for me since you can just manually edit and file in the future. imo they aren't needed or at least I haven't seen a case where i need admin credentials on a forwarder&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 19:46:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602476#M12906</guid>
      <dc:creator>pc1</dc:creator>
      <dc:date>2022-06-20T19:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602479#M12907</link>
      <description>&lt;P&gt;First things first - it's not to say that the script does 't work or anything like that. It's just that I'm already old and grumpy &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; and like well-written stuff so I point out what can be done better.&lt;/P&gt;&lt;P&gt;1) No. I mean private keys/certs for TLS. If it was my script and it was meant to be universal I'd do a conditional check for existence of old forwarder and a command-line switch to force removal in case of pre-existing dir.&lt;/P&gt;&lt;P&gt;2) Sure it doesn't it simply connects to a server and pulls a file from there. Where are elevated privileges needed here? Nowhere. You just need to be able to write a file in the destination&amp;nbsp; directory.&lt;/P&gt;&lt;P&gt;3) The "pretty" solution would be to use mktemp to create a temporary directory (probably somewhere in /tmp) and delete it at the end of the script. Bonus points for capturing error states and removing the package on abnormal exit (but to be quite honest I'm usually too lazy to implement it myself).&lt;/P&gt;&lt;P&gt;7) btool might need them (especially if you want to run it without direct sudo/su to the user running the forwarder. Also listing inputs and monitor states. Sometimes these credentials are nice to have.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 19:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602479#M12907</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-06-20T19:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: bash script , automating splunkforwarder installation.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602484#M12908</link>
      <description>&lt;P&gt;This is great constructive feedback of several things I didn't know about. Thank you&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":raising_hands:"&gt;🙌&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 20:42:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Has-anyone-written-a-bash-script-to-install-splunkforwarder-on-a/m-p/602484#M12908</guid>
      <dc:creator>pc1</dc:creator>
      <dc:date>2022-06-20T20:42:53Z</dc:date>
    </item>
  </channel>
</rss>

