<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk UF Linux : How To Automate Installation in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762672#M120746</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/314750"&gt;@0xAli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on your Linux OS you might be able to use the rpm install package option with the kickstarter file, check out&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/9.1/install-splunk-enterprise-on-linux-or-macos/install-on-linux" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/9.1/install-splunk-enterprise-on-linux-or-macos/install-on-linux &lt;/A&gt;for more info.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Personally I would probably look to go at using something like Ansible as an orchestration tool, there is a Splunk Ansible repo which might also be useful as a starting point. Ansible is a great way to deploy out to multiple server that you have SSH access to.&lt;/P&gt;&lt;P&gt;There is a bunch of useful links and comments on the following which might give you some ideas too:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-Ansible-script-to-automate-installation-of-splunk/m-p/551627" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-Ansible-script-to-automate-installation-of-splunk/m-p/551627&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you? If so, please consider&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Aug 2026 09:41:08 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2026-08-03T09:41:08Z</dc:date>
    <item>
      <title>Splunk UF Linux : How To Automate Installation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762671#M120745</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;As per the below the Splunk Linux UF installation isn't single command as Splunk MS UF, and the customer doen't have a deployment tool, going with more than 100 UF with manually steps is a huge time.&lt;BR /&gt;&lt;BR /&gt;Anyone has an idea to automate the process?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/forward-and-process-data/universal-forwarder-manual/9.4/install-the-universal-forwarder/install-a-nix-universal-forwarder" target="_self"&gt;https://help.splunk.com/en/splunk-cloud-platform/forward-and-process-data/universal-forwarder-manual/9.4/install-the-universal-forwarder/install-a-nix-universal-forwarder&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 09:25:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762671#M120745</guid>
      <dc:creator>0xAli</dc:creator>
      <dc:date>2026-08-03T09:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Linux : How To Automate Installation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762672#M120746</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/314750"&gt;@0xAli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on your Linux OS you might be able to use the rpm install package option with the kickstarter file, check out&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/9.1/install-splunk-enterprise-on-linux-or-macos/install-on-linux" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/9.1/install-splunk-enterprise-on-linux-or-macos/install-on-linux &lt;/A&gt;for more info.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Personally I would probably look to go at using something like Ansible as an orchestration tool, there is a Splunk Ansible repo which might also be useful as a starting point. Ansible is a great way to deploy out to multiple server that you have SSH access to.&lt;/P&gt;&lt;P&gt;There is a bunch of useful links and comments on the following which might give you some ideas too:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-Ansible-script-to-automate-installation-of-splunk/m-p/551627" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-can-I-get-Ansible-script-to-automate-installation-of-splunk/m-p/551627&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you? If so, please consider&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 09:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762672#M120746</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-08-03T09:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Linux : How To Automate Installation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762682#M120753</link>
      <description>&lt;P&gt;To be honest, I have no idea what "kickstart file" the docs refer to here. The only kickstart file with RH and RH-based distros I know is the kickstart you can write to automate the OS installation.&lt;/P&gt;&lt;P&gt;And generally, at scale, probably the most maintainable solution is to install a clean UF, drop in an app pointing to deployment server (and maybe another one with local Root CA certs if you're using one) and enable boot-start, start service whichever way you feel most comfortable with - shell script, ansible, whatever.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 20:01:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762682#M120753</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-08-03T20:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Linux : How To Automate Installation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762686#M120757</link>
      <description>&lt;P&gt;My historical answer was I built a second RPM that deployed enough configuration bits to the Splunk forwarder, required the Splunk forwarder RPM, and ensured that the forwarder was started.&lt;/P&gt;&lt;P&gt;In other words, it wrote a Splunk app into the Forwarder's /opt/splunkforwarder/etc/apps that set up talking to the deployment server to get the rest of the configurations, ensured boot-start was set, and that it started/restarted the forwarder after deployment.&amp;nbsp; It wasn't hard to create as a custom rpm/dpkg.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That way, I used the same deployment mechanism as all other packages and could ensure all the site-local bits were there, and just "install this package, which forces installation of the Splunk UF" was all they had to do.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 22:57:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762686#M120757</guid>
      <dc:creator>mmccul</dc:creator>
      <dc:date>2026-08-03T22:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF Linux : How To Automate Installation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762692#M120758</link>
      <description>&lt;P&gt;This is one of the possible methods - we used a similar approach for some packages in $job-2 - build a custom RPM named &amp;lt;something&amp;gt;-stdconf which would depend on the base package and would perform configuration steps, enable the service, set up users and so on.&lt;/P&gt;&lt;P&gt;But I'm not a big fan of this approach - RPMs are not well suited for this and - especially if the base package changes (like Splunk's migration from splunk to splunkforwarder user) you have to handle a lot of transition cases. And it quickly gets messy.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2026 06:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-Linux-How-To-Automate-Installation/m-p/762692#M120758</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-08-04T06:40:08Z</dc:date>
    </item>
  </channel>
</rss>

