<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Powershell for splunk forwarder installation in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570998#M10743</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236717"&gt;@Stefanie&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Yes please.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-panel lia-panel-standard MessageTagsTaplet Chrome lia-component-message-view-widget-tags"&gt;&lt;DIV class="lia-decoration-border"&gt;&lt;DIV class="lia-decoration-border-top"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-decoration-border-content"&gt;&lt;DIV&gt;&lt;DIV class="lia-panel-content-wrapper"&gt;&lt;DIV class="lia-panel-content"&gt;&lt;DIV class="AddMessageTags lia-message-tags"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 14 Oct 2021 13:32:24 GMT</pubDate>
    <dc:creator>koe600</dc:creator>
    <dc:date>2021-10-14T13:32:24Z</dc:date>
    <item>
      <title>Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570973#M10732</link>
      <description>&lt;P&gt;I can't make this script work for forwarder deployment. It takes up a lot of time to deploy to many servers..&lt;/P&gt;&lt;P&gt;I guess it has som obvious flaw that i can't see...&lt;BR /&gt;My script:&lt;/P&gt;&lt;P&gt;[Edit]&lt;/P&gt;&lt;P&gt;$DEPLOYMENT_SERVER="SPLUNK-05:8089"&lt;BR /&gt;$RECEIVING_INDEXER="SPLUNK-05:9997"&lt;BR /&gt;$MONITOR_PATH="C:\Temp\"&lt;BR /&gt;$CERTFILE="c:\temp\cert.pfx"&lt;BR /&gt;$CERTPASSWORD="pass"&lt;BR /&gt;$LOGON_USERNAME="Admin"&lt;BR /&gt;$LOGON_PASSWORD="pass"&lt;BR /&gt;$SET_ADMIN_USER=1&lt;BR /&gt;$SPLUNKUSERNAME="Admin"&lt;BR /&gt;$SPLUNKPASSWORD="pass"&lt;BR /&gt;$AGREETOLICENSE="yes"&lt;/P&gt;&lt;P&gt;msiexec.exe /i "\\server\splunkforwarder-8.1.2-545206cc9f70-x64-release.msi" DEPLOYMENT_SERVER=$DEPLOYMENT_SERVER RECEIVING_INDEXER=$RECEIVING_INDEXER MONITOR_PATH=$MONITOR_PATH CERTFILE=$CERTFILE CERTPASSWORD=$CERTPASSWORD SET_ADMIN_USER=$SET_ADMIN_USER SPLUNKUSERNAME=$SPLUNKUSERNAME SPLUNKPASSWORD=$SPLUNKPASSWORD AGREETOLICENSE=$AGREETOLICENSE /Quiet&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 13:28:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570973#M10732</guid>
      <dc:creator>koe600</dc:creator>
      <dc:date>2021-10-14T13:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570974#M10733</link>
      <description>&lt;P&gt;Is this script too slow to deploy for your organization? I have a powershell script that we use at my organization. I can share it with you if you'd like.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 12:48:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570974#M10733</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2021-10-14T12:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570977#M10734</link>
      <description>&lt;P&gt;Question is what error you get. "I can't make it work" is not very descriptive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 12:54:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570977#M10734</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-14T12:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570983#M10736</link>
      <description>&lt;P&gt;No error.&lt;BR /&gt;If i run with /quiet, the script ends instantly.&lt;BR /&gt;If i run the script without /quiet, it just opens the regular install dialog..&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Seems like it doesn't care about all the arguments..&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 13:02:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570983#M10736</guid>
      <dc:creator>koe600</dc:creator>
      <dc:date>2021-10-14T13:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570984#M10737</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239684"&gt;@koe600&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The syntax for setting properties on the msiexec.exe command line is simply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;NAME=value&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Not:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/NAME=value&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 13:07:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570984#M10737</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2021-10-14T13:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570989#M10740</link>
      <description>&lt;P&gt;As &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225785"&gt;@jho-splunk&lt;/a&gt; noticed, you put variables as simply key=value pairs, not with a slash, as msiexec parameter.&lt;/P&gt;&lt;P&gt;That's one.&lt;/P&gt;&lt;P&gt;But the other thing that looks strange is those backticks - are they because of you pasting here the command or do you have them in your original command?&lt;/P&gt;&lt;P&gt;EDIT: Oh, and to agree to a license you have to specify Yes/No, not 1/0.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PickleRick_0-1634217229349.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16430i44ADBAD798976F54/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PickleRick_0-1634217229349.png" alt="PickleRick_0-1634217229349.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 13:13:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570989#M10740</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-14T13:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570990#M10741</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225785"&gt;@jho-splunk&lt;/a&gt; : The original script doesn't contain slashes, just me trying to figure out wht it doesn't work.&lt;/P&gt;&lt;P&gt;I removed the slashes from the post now, i realize it would create confusion.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 13:13:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570990#M10741</guid>
      <dc:creator>koe600</dc:creator>
      <dc:date>2021-10-14T13:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570997#M10742</link>
      <description>&lt;P&gt;@&lt;SPAN&gt;PickleRick: I pasted a "working" version of the script. I see now that i had posted a tweaked version..&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 13:30:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570997#M10742</guid>
      <dc:creator>koe600</dc:creator>
      <dc:date>2021-10-14T13:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570998#M10743</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236717"&gt;@Stefanie&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Yes please.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-panel lia-panel-standard MessageTagsTaplet Chrome lia-component-message-view-widget-tags"&gt;&lt;DIV class="lia-decoration-border"&gt;&lt;DIV class="lia-decoration-border-top"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-decoration-border-content"&gt;&lt;DIV&gt;&lt;DIV class="lia-panel-content-wrapper"&gt;&lt;DIV class="lia-panel-content"&gt;&lt;DIV class="AddMessageTags lia-message-tags"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 14 Oct 2021 13:32:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570998#M10743</guid>
      <dc:creator>koe600</dc:creator>
      <dc:date>2021-10-14T13:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570999#M10744</link>
      <description>&lt;LI-CODE lang="markup"&gt;$Environment = [System.Net.Dns]::GetHostByName(($env:COMPUTERNAME))
Write-Host "This script will only work as admin!" -BackgroundColor Magenta

#Installs the Splunk Forwarder
Start-Process -FilePath C:\Windows\system32\msiexec.exe -ArgumentList "/i splunkforwarder-8.2.0-e053ef3c985f-x64-release.msi AGREETOLICENSE=Yes SERVICESTARTTYPE=auto GENRANDOMPASSWORD=1 /quiet" -Wait -NoNewWindow

#Stop the Splunk Universal Forwarder
Write-Host "Stopping the Splunk Forwarder Service"
Stop-Service -Name SplunkForwarder
Start-Sleep -Seconds 5

#Copy the zzz_config file into the Splunk Program Files
Write-Host "Copying the configuration files"
Copy-Item -Path .\zzz_config_base -Recurse -Destination "C:\Program Files\SplunkUniversalForwarder\etc\apps\"
Start-Sleep -Seconds 5

#Restart the splunk service
Do{
    
    Write-Host "Attempting to restart Splunk Forwarder Service"
    Start-Service -Name SplunkForwarder
    Start-Sleep -Seconds 10

    $Splunk = Get-Service -Name SplunkForwarder 
}until($Splunk.Status -eq "Running")
Write-Host "Splunk Service restarted successfully" -ForegroundColor Green&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the folder of my script I have another folder named "zzz_config_base" and in that folder, a "local" folder, and in the local folder is my deploymentclient.conf file which you can create. That conf file has your information to point the forwarder to your Deployment Server.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 13:42:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/570999#M10744</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2021-10-14T13:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/571067#M10754</link>
      <description>&lt;P&gt;OK. I tried to run your script. Did you look into the event log?&lt;/P&gt;&lt;P&gt;In my case (I already have older version of UF installed), I get EventID 11730&lt;/P&gt;&lt;P&gt;Product: UniversalForwarder -- Error 1730. You must be an Administrator to remove this application. To remove this application, you can log on as an Administrator, or contact your technical support group for assistance.&lt;/P&gt;&lt;P&gt;If I remove the /quiet switch, indeed the installer starts interactively.&lt;/P&gt;&lt;P&gt;Try adding /L*v some\log\file.txt and review the file after the install starts and terminates.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 08:38:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/571067#M10754</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-15T08:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell for splunk forwarder installation</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/571471#M10758</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236717"&gt;@Stefanie&lt;/a&gt;&amp;nbsp;Your script worked well with a few adapations. Thx!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 07:24:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-for-splunk-forwarder-installation/m-p/571471#M10758</guid>
      <dc:creator>koe600</dc:creator>
      <dc:date>2021-10-19T07:24:16Z</dc:date>
    </item>
  </channel>
</rss>

