<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder installation on remote host in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753943#M119677</link>
    <description>&lt;P&gt;I need to install it on few number of servers, could you please explain what steps I need to follow to get it installed with the help of server team manually for windows and linux machine?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 04 Oct 2025 09:35:29 GMT</pubDate>
    <dc:creator>maheshnc</dc:creator>
    <dc:date>2025-10-04T09:35:29Z</dc:date>
    <item>
      <title>Universal Forwarder installation on remote host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753940#M119675</link>
      <description>&lt;P&gt;We need to install UF on remote application servers (linux/windows) but as a splunk admin, I don't have direct access (ssh/rdp) to these servers, in such case how can I proceed with UF installation on these servers? Also, how to decide UF version to be installed on these servers?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Oct 2025 09:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753940#M119675</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-10-04T09:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder installation on remote host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753942#M119676</link>
      <description>&lt;P&gt;You can't install something on a server without access to that server. That would be a severe security vulnerability if you could. UF deployment is something you usually work on with the local (un)friendly admin team. On a small scale it can be done manually, in bigger environments it's usually either scripted and pushed from GPO or deployed using another enpoint managing software. The UF may also be bundled in a standard deployment image for the OS. It's all to be discussed with the OS admins.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Oct 2025 09:18:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753942#M119676</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-10-04T09:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder installation on remote host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753943#M119677</link>
      <description>&lt;P&gt;I need to install it on few number of servers, could you please explain what steps I need to follow to get it installed with the help of server team manually for windows and linux machine?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Oct 2025 09:35:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753943#M119677</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-10-04T09:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder installation on remote host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753944#M119678</link>
      <description>&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/universal-forwarder-manual/10.0/install-the-universal-forwarder" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/universal-forwarder-manual/10.0/install-the-universal-forwarder&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Oct 2025 09:54:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753944#M119678</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-10-04T09:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder installation on remote host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753954#M119681</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;said it's really difficoult to install an UF without accessing the remote server, the only way is, on Windows using Group Policy Server, but I cannot help you because you n eed a Windows specialist, or a Software distribution server, like Ansible, and use it, but anyway, Ansible uses SSH and RDP to install packages on a remote system.&lt;/P&gt;&lt;P&gt;About the version to install, you should identify the last certified version for you Operative System on&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/download/universal-forwarder.html" target="_blank"&gt;https://www.splunk.com/en_us/download/universal-forwarder.html&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;In addition it depends on the version of other installed Splunk: the Universal Forwarder version must be the same or lower than the following Splunk Server, in other words, if you have an Indexer 9.4.1, the higher version you can use is 9.4.1 depending on the Operative System of the machine.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2025 08:09:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753954#M119681</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-10-05T08:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder installation on remote host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753955#M119682</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; said, you will need some way of getting the UF installation onto the remote server, this will ultimately depend on your organisation, scale, policies etc.&lt;/P&gt;&lt;P&gt;Some potential options for you that I've experienced before:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Work with Server Owners -&amp;nbsp;&lt;/STRONG&gt;PRovide the UF installation package and deployment instructions to the server administrators and/or share deployment scripts that can be executed by local admins&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Use Deployment Management Tools - &lt;/STRONG&gt;If there are&amp;nbsp;existing enterprise deployment tools such as Ansible, Puppet, Terraform) then leverage these - this could be by raising a change to their Git codebase to get the UFs installed, this is often something you might see&amp;nbsp;in large environments.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Request Temporary Access &lt;/STRONG&gt;-&amp;nbsp;Request temporary admin access through change management processes to install manually.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Once deployed, configure them to connect to your Deployment Server and use the DS to push out any configurations to manage the UFs as this&amp;nbsp;handles ongoing configuration management without needing server access.&lt;/P&gt;&lt;P&gt;Regarding the version to deploy, this might depend on your organisation's policy around maintaining software versions however check out&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/compatibility-matrix/splunk-products-version-compatibility/compatibility-between-forwarders-and-splunk-enterprise-indexers" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates/compatibility-matrix/splunk-products-version-compatibility/compatibility-between-forwarders-and-splunk-enterprise-indexers&lt;/A&gt;&amp;nbsp;for a matrix of version compatibility.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2025 09:39:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753955#M119682</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-10-05T09:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder installation on remote host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753961#M119683</link>
      <description>&lt;P&gt;One more comment about the configuration to connect your indexers or DS.&lt;/P&gt;&lt;P&gt;Depending on how you install your configurations on those systems you must have almost always some configuration package to install with first time binary installation. In minimum this is package (splunk app) that contains information and needed certs to connect to Your Splunk Indexers. This apply if you are installing your collection apps via GPO, Ansible, manually or some other configuration tool. If you are using DS (deployment server) to deliver app configuration then you must install also DS client package into those UFs. Then just us DS as normally is used to deliver other packages.&lt;/P&gt;&lt;P&gt;In that way you can see immediately, after UFs has installed and configured to configure your system, internal logs from those new UF. If/when you have configure some alerts for unknown logs then you can react and continue with onboarding process as planned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2025 13:25:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753961#M119683</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-10-05T13:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder installation on remote host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753982#M119688</link>
      <description>&lt;P&gt;So, in this case, can I download the installer and upload it to the onedrive and then ask Application team to copy it to the remote server and install, once installed then configure the inputs.conf, outputs.conf and deploymentclient.conf?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2025 10:27:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753982#M119688</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-10-06T10:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder installation on remote host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753994#M119690</link>
      <description>&lt;P&gt;Basically yes.&lt;/P&gt;&lt;P&gt;I do it like:&lt;/P&gt;&lt;P&gt;There some differences between SCP and Splunk Enterprise!&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;&lt;P&gt;outputs.conf&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;SCP:&lt;/STRONG&gt; Copy Splunk Universal Forwarder package from stack e.g. &lt;EM&gt;&lt;STRONG&gt;https://&amp;lt;STACK NAME&amp;gt;.splunkcloud.com/en-GB/app/splunkclouduf/setupuf (Download Universal Forwarder Credentials)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Splunk Enterprise&lt;/STRONG&gt;: Create / update / check Customer’s zzz_base_lnx_uf or zzz_base_win_uf configuration from GIT. There could be several if there are several environments and/or several target where clients are sending events.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;DS definitions&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;&lt;P&gt;Create / update / check Customer’s zzz_base_ds_uf configuration from GIT. There could be several if there are several environments and/or several DS defined.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Copy msi for UF and base uf module to target node or whatever you are using for install it&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Next&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;msiexec.exe /i &amp;lt;path to temp&amp;gt;/splunkforwarder-&amp;lt;XXXXX&amp;gt;-x64-release.msi AGREETOLICENSE=yes LAUNCHSPLUNK=no SERVICESTARTTYPE=auto /quiet /l*v install-log.txt&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Add correct UF package under etc\apps\ (both DS and UF packages).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Start SplunkForwarder service&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;After that you should have connections between UF and DS and UF and indexers. Then you can see UF's internal logs from your normal SH and also check and modify UF's inputs on DS side.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2025 14:10:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-installation-on-remote-host/m-p/753994#M119690</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-10-06T14:10:54Z</dc:date>
    </item>
  </channel>
</rss>

