<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Universal Forwarder Deployment with SCCM in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-Deployment-with-SCCM/m-p/218722#M42985</link>
    <description>&lt;P&gt;Could be the "/q" switch SCCM adds to packages when it deploys them.&lt;BR /&gt;
Splunk already has a "/quiet" switch and the two together will prevent SCCM from deploying it.&lt;BR /&gt;
You'll need to create a batch file which executes the MSI to get around this problem.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Nov 2015 00:04:56 GMT</pubDate>
    <dc:creator>shartwell</dc:creator>
    <dc:date>2015-11-06T00:04:56Z</dc:date>
    <item>
      <title>Splunk Universal Forwarder Deployment with SCCM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-Deployment-with-SCCM/m-p/218719#M42982</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We are trying to deploy the Splunk Universal Forwarder using Microsoft SCCM. I can successfully install the MSI from the command line using:&lt;/P&gt;

&lt;P&gt;msiexec /i "splunkforwarder-6.3.0-aa7d4b1ccb80-x64-release.msi" AGREETOLICENSE=Yes DEPLOYMENT_SERVER="&lt;EM&gt;mydeploymentserver&lt;/EM&gt;:8089" /quiet&lt;/P&gt;

&lt;P&gt;However when our SCCM admin uses the same command in his deployment manager, the installation fails. According to the SCCM log, the error is:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;[LOG[Failed to clear product&amp;gt; advertisement, error code&amp;gt; 1603]LOG]!&amp;gt; date="10-29-2015" component="execmgr"&amp;gt; context="" type="3" thread="17300"&amp;gt; file="msiexecution.cpp:264"&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I know this is most likely an SCCM issue, but wanted to see if anyone out there has received a similar error or had a similar issue.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 13:28:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-Deployment-with-SCCM/m-p/218719#M42982</guid>
      <dc:creator>asofo</dc:creator>
      <dc:date>2015-11-04T13:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder Deployment with SCCM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-Deployment-with-SCCM/m-p/218720#M42983</link>
      <description>&lt;P&gt;Sounds like this:&lt;BR /&gt;
&lt;A href="https://support.microsoft.com/en-us/kb/834484"&gt;https://support.microsoft.com/en-us/kb/834484&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 14:29:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-Deployment-with-SCCM/m-p/218720#M42983</guid>
      <dc:creator>bohanlon_splunk</dc:creator>
      <dc:date>2015-11-04T14:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder Deployment with SCCM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-Deployment-with-SCCM/m-p/218721#M42984</link>
      <description>&lt;P&gt;I saw that earlier, but the machines are Windows 7 and I checked all permissions. The weird thing is that there weren't any problems with the 6.0.1 version of the Universal Forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 16:58:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-Deployment-with-SCCM/m-p/218721#M42984</guid>
      <dc:creator>asofo</dc:creator>
      <dc:date>2015-11-04T16:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder Deployment with SCCM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-Deployment-with-SCCM/m-p/218722#M42985</link>
      <description>&lt;P&gt;Could be the "/q" switch SCCM adds to packages when it deploys them.&lt;BR /&gt;
Splunk already has a "/quiet" switch and the two together will prevent SCCM from deploying it.&lt;BR /&gt;
You'll need to create a batch file which executes the MSI to get around this problem.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 00:04:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-Deployment-with-SCCM/m-p/218722#M42985</guid>
      <dc:creator>shartwell</dc:creator>
      <dc:date>2015-11-06T00:04:56Z</dc:date>
    </item>
  </channel>
</rss>

