<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remotely run .spl file in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/568074#M10679</link>
    <description>&lt;P&gt;I gave that a try but the computer still doesn't show up in the cloud.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Sep 2021 14:59:21 GMT</pubDate>
    <dc:creator>Kat7</dc:creator>
    <dc:date>2021-09-22T14:59:21Z</dc:date>
    <item>
      <title>Remotely run .spl file</title>
      <link>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/567904#M10677</link>
      <description>&lt;P&gt;I'm working on building a remote deployment for the Splunk Universal Forwarder with PDQ Deploy on our Windows 10 computers.&amp;nbsp; I can run the initial splunk forwarder .msi installation without issue, but when I try to run the .spl file to sync the computer to our Splunk cloud environment, it errors out every time.&lt;/P&gt;&lt;P&gt;The command I'm using works fine when I run it locally, but I get "login failed" when I run it through PDQ.&lt;/P&gt;&lt;P&gt;cd "C:\Program Files\SplunkUniversalForwarder\bin"&lt;BR /&gt;splunk install app \splunkclouduf.spl -auth &lt;EM&gt;username&lt;/EM&gt;:&lt;EM&gt;password&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Is there a tweak I can make to the command or another way to accomplish the sync to our cloud environment?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 19:41:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/567904#M10677</guid>
      <dc:creator>Kat7</dc:creator>
      <dc:date>2021-09-21T19:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Remotely run .spl file</title>
      <link>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/567941#M10678</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Could you try to unpack the splunkclouduf.spl package and move it to the C:\Program Files\SplunkUniversalForwarder\etc\apps\ folder and then restart the UF instance?&lt;/P&gt;&lt;P&gt;Something like that:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;tar xvf splunkclouduf.spl

mv &amp;lt;extracted_folder&amp;gt; C:\Program Files\SplunkUniversalForwarder\etc\apps\

splunk restart&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 04:30:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/567941#M10678</guid>
      <dc:creator>danielcj</dc:creator>
      <dc:date>2021-09-22T04:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Remotely run .spl file</title>
      <link>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/568074#M10679</link>
      <description>&lt;P&gt;I gave that a try but the computer still doesn't show up in the cloud.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 14:59:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/568074#M10679</guid>
      <dc:creator>Kat7</dc:creator>
      <dc:date>2021-09-22T14:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Remotely run .spl file</title>
      <link>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/677496#M13639</link>
      <description>&lt;P&gt;I am having this same issue were you able to resolve it? If so, what steps did you take?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 23:26:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/677496#M13639</guid>
      <dc:creator>Cliff-M</dc:creator>
      <dc:date>2024-02-13T23:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: Remotely run .spl file</title>
      <link>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/677553#M13646</link>
      <description>&lt;P&gt;What I ended up doing was copying the .spl file here (after creating the Desktop folder)&amp;nbsp;C:\Program Files\SplunkUniversalForwarder\bin\Desktop.&lt;/P&gt;&lt;P&gt;Then I copy the applicable Forwarder Management app folders are here:&amp;nbsp;C:\Program Files\SplunkUniversalForwarder\etc\apps.&amp;nbsp; The best way I found was to compare the folders on your test machine to a computer that you previously set up "correctly," and then copy over any missing folders.&amp;nbsp; These will generally be the same folders every time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I open an administrator command prompt and run these commands:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; cd "C:\Program Files\SplunkUniversalForwarder\bin"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; splunk restart&lt;BR /&gt;Once the last command finishes, you should be good to go.&lt;BR /&gt;&lt;BR /&gt;My PDQ deployment looks like this:&lt;BR /&gt;Step 1: Install Universal Forwarder&lt;BR /&gt;Step 2: Powershell script&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; New-Item -ItemType "directory" -Path "c:\\program Files\SplunkUniversalForwarder\bin\Desktop"&lt;BR /&gt;Step 3: File Copy- Copy .spl file into the folder created in step 2.&lt;BR /&gt;Step4: File Copy- Copy any needed app folders into here (if multiple app folders need to be copied over, each folder will be its own step in PDQ):&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; c:\\Program Files\SplunkUniversalForwarder\etc\apps&lt;BR /&gt;Step 5: Command Prompt-&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;cd "C:\Program Files\SplunkUniversalForwarder\bin"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; splunk restart&lt;BR /&gt;&lt;BR /&gt;Hope this is helpful!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 13:07:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Remotely-run-spl-file/m-p/677553#M13646</guid>
      <dc:creator>Kat7</dc:creator>
      <dc:date>2024-02-14T13:07:40Z</dc:date>
    </item>
  </channel>
</rss>

