<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to install Splunk forwarder with powershell? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/618804#M12044</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;We are starting to integrate spunk into our systems, and in order to make sure everything goes smoothly we want to write a PowerShell script for the installation.&lt;/P&gt;
&lt;P&gt;We use Splunk Cloud, so we are unsure if there is a way to set a PowerShell script to install it across our systems. We would like guidance where possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Sat, 29 Oct 2022 00:21:39 GMT</pubDate>
    <dc:creator>JacksonModlin</dc:creator>
    <dc:date>2022-10-29T00:21:39Z</dc:date>
    <item>
      <title>How to install Splunk forwarder with powershell?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/618804#M12044</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;We are starting to integrate spunk into our systems, and in order to make sure everything goes smoothly we want to write a PowerShell script for the installation.&lt;/P&gt;
&lt;P&gt;We use Splunk Cloud, so we are unsure if there is a way to set a PowerShell script to install it across our systems. We would like guidance where possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2022 00:21:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/618804#M12044</guid>
      <dc:creator>JacksonModlin</dc:creator>
      <dc:date>2022-10-29T00:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder Install with powershell</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/618807#M12045</link>
      <description>&lt;P&gt;This answer should help:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Powershell-unattended-installation/m-p/81069" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Powershell-unattended-installation/m-p/81069&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The installation instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.0.1/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller#Install_a_Windows_universal_forwarder_from_the_command_line" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/9.0.1/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller#Install_a_Windows_universal_forwarder_from_the_command_line&lt;/A&gt;&amp;nbsp;should help you understand what the script is doing.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 23:31:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/618807#M12045</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-28T23:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder Install with powershell</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/618912#M12046</link>
      <description>&lt;P&gt;I saw many posts like this one, looking at install the forwarder using PowerShell, but we need to install it for splunk cloud, will it still work, or will we have to install everything manually?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 12:56:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/618912#M12046</guid>
      <dc:creator>JacksonModlin</dc:creator>
      <dc:date>2022-10-31T12:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder Install with powershell</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/618930#M12047</link>
      <description>&lt;P&gt;Forwarders are installed the same way for Splunk Cloud as for Splunk Enterprise.&lt;/P&gt;&lt;P&gt;For Splunk Cloud, there is an additional step to install the Splunk Cloud credentials.&amp;nbsp; Get the creds by going to the Universal Forwarder app on your Splunk Cloud search head and clicking on the green Download button.&amp;nbsp; The downloaded file should be expanded into the SplunkUniversalForwarder\etc\apps folder.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 14:06:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/618930#M12047</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-31T14:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder Install with powershell</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619016#M12048</link>
      <description>&lt;P&gt;We tried this, and it failed. It keeps trying to install it as a splunk enterprise instance instead of splunk cloud, is there a flag we can use to make the version of the forwarder into a splunk cloud instance????&lt;/P&gt;&lt;P&gt;Attached is our log file, please provide guidance whenever possible.&amp;nbsp;&lt;/P&gt;&lt;P&gt;```&lt;/P&gt;&lt;P&gt;10-31-2022 14:44:12.078 -0500 INFO LMStackMgr [0 MainThread] - Initializing CleMgr...&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LicenseMgr [0 MainThread] - Initing LicenseMgr&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMConfig [0 MainThread] - serverName=IT-JMODLIN guid=96BF5E48-20C5-4825-AA20-94D331BD980E&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMConfig [0 MainThread] - connection_timeout=30&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMConfig [0 MainThread] - send_timeout=30&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMConfig [0 MainThread] - receive_timeout=30&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMConfig [0 MainThread] - key=license_warnings_update_interval not found in licenser stanza of server.conf, defaulting=0&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMConfig [0 MainThread] - squash_threshold=2000&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMConfig [0 MainThread] - strict_pool_quota=1&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMConfig [0 MainThread] - key=pool_suggestion not found in licenser stanza of server.conf, defaulting=''&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMConfig [0 MainThread] - key=test_aws_metering not found in licenser stanza of server.conf, defaulting=0&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMConfig [0 MainThread] - key=test_aws_product_code not found in licenser stanza of server.conf, defaulting=0&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LicenseMgr [0 MainThread] - Initing LicenseMgr runContext_splunkd=false&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMStackMgr [0 MainThread] - closing stack mgr&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMSlaveInfo [0 MainThread] - all slaves cleared&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMStackMgr [0 MainThread] - Initalized license_warnings_update_interval=auto&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMStackMgr [0 MainThread] - License Manager supports Conditional Licensing Enforcement. For baked in CLE policies, window_period=60 days, max_violations=45, for stack size below 107374182400 bytes&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMLicense [0 MainThread] - Applying default enforcement policy for free&lt;BR /&gt;10-31-2022 14:44:12.079 -0500 INFO LMStackMgr [0 MainThread] - Added policy WinSz=30 Warnings=3 MaxSize=0 isDefault=1 features= for free&lt;BR /&gt;10-31-2022 14:44:12.080 -0500 INFO LMLicense [0 MainThread] - Applying default enforcement policy for forwarder&lt;BR /&gt;10-31-2022 14:44:12.080 -0500 INFO LMStackMgr [0 MainThread] - Added policy WinSz=30 Warnings=5 MaxSize=0 isDefault=1 features= for forwarder&lt;BR /&gt;10-31-2022 14:44:12.081 -0500 INFO LMStack [0 MainThread] - Added type=forwarder license, from file=splunkforwarder.lic, to stack=forwarder of group=Forwarder&lt;BR /&gt;10-31-2022 14:44:12.081 -0500 INFO LMLicense [0 MainThread] - Applying default enforcement policy for forwarder&lt;BR /&gt;10-31-2022 14:44:12.081 -0500 INFO LMStackMgr [0 MainThread] - created stack='forwarder'&lt;BR /&gt;10-31-2022 14:44:12.081 -0500 INFO LMStackMgr [0 MainThread] - Replaced with latest policy WinSz=30 Warnings=5 MaxSize=0 isDefault=1 features= for forwarder&lt;BR /&gt;10-31-2022 14:44:12.081 -0500 INFO LMStackMgr [0 MainThread] - Initialized hideQuotaWarning = "0"&lt;BR /&gt;10-31-2022 14:44:12.081 -0500 INFO LMStackMgr [0 MainThread] - init completed [96BF5E48-20C5-4825-AA20-94D331BD980E,Forwarder,runContext_splunkd=false]&lt;BR /&gt;10-31-2022 14:44:12.081 -0500 INFO LicenseMgr [0 MainThread] - StackMgr init complete...&lt;BR /&gt;10-31-2022 14:44:12.081 -0500 INFO LMTracker [0 MainThread] - Setting default product type='enterprise'&lt;BR /&gt;10-31-2022 14:44:12.081 -0500 INFO LMTracker [0 MainThread] - this is not splunkd, will perform partial init&lt;BR /&gt;10-31-2022 14:44:12.081 -0500 INFO LicenseMgr [0 MainThread] - Tracker init complete...&lt;BR /&gt;10-31-2022 14:44:12.086 -0500 INFO KVStorageEngineUpgrade [0 MainThread] - Setting parallelDumpCollectionJobs=0 parallelRestoreCollectionJobs=0 based on max_num_cpus=8 and total_configured_collections=0, insertionWorkersPerCollection=1 as maxInsertionWorkersPerCollection=4&lt;BR /&gt;10-31-2022 14:44:12.090 -0500 INFO KVStoreBackupRestore [0 MainThread] - Before KV Store engine migration: KVStoreDbsize=4096 fsBytesFree=90732716032&lt;BR /&gt;10-31-2022 14:44:12.090 -0500 WARN SSLOptions [17672 MainThread] - server.conf/[kvstore]/sslVerifyServerCert is false disabling certificate validation; must be set to "true" for increased security&lt;BR /&gt;10-31-2022 14:44:12.094 -0500 INFO MongodRunner [17672 MainThread] - Starting mongod with executable name=mongod-4.0.exe version=kvstore version 4.0&lt;BR /&gt;10-31-2022 14:44:12.094 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --dbpath C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\kvstore\mongo&lt;BR /&gt;10-31-2022 14:44:12.094 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --storageEngine wiredTiger&lt;BR /&gt;10-31-2022 14:44:12.094 -0500 INFO MongodRunner [17672 MainThread] - Using cacheSize=2.25GB&lt;BR /&gt;10-31-2022 14:44:12.094 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --port 8191&lt;BR /&gt;10-31-2022 14:44:12.094 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --timeStampFormat iso8601-utc&lt;BR /&gt;10-31-2022 14:44:12.094 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --oplogSize 200&lt;BR /&gt;10-31-2022 14:44:12.095 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --keyFile C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\kvstore\mongo\splunk.key&lt;BR /&gt;10-31-2022 14:44:12.095 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --setParameter enableLocalhostAuthBypass=0&lt;BR /&gt;10-31-2022 14:44:12.095 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --setParameter oplogFetcherSteadyStateMaxFetcherRestarts=0&lt;BR /&gt;10-31-2022 14:44:12.095 -0500 INFO MongodRunner [17672 MainThread] - Starting mongod in standalone mode&lt;BR /&gt;10-31-2022 14:44:12.095 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --bind_ip=0.0.0.0 (all ipv4 addresses)&lt;BR /&gt;10-31-2022 14:44:12.095 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --sslMode requireSSL&lt;BR /&gt;10-31-2022 14:44:12.095 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --sslAllowInvalidHostnames&lt;BR /&gt;10-31-2022 14:44:12.321 -0500 INFO MongodRunner [17672 MainThread] - Found an existing PFX certificate&lt;BR /&gt;10-31-2022 14:44:12.321 -0500 INFO MongodRunner [17672 MainThread] - Found an existing PFX certificate&lt;BR /&gt;10-31-2022 14:44:12.321 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --sslCertificateSelector subject=SplunkServerDefaultCert&lt;BR /&gt;10-31-2022 14:44:12.321 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --sslAllowInvalidCertificates&lt;BR /&gt;10-31-2022 14:44:12.321 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --sslAllowConnectionsWithoutCertificates&lt;BR /&gt;10-31-2022 14:44:12.321 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --sslDisabledProtocols noTLS1_0,noTLS1_1&lt;BR /&gt;10-31-2022 14:44:12.321 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --sslCipherConfig ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128-GCM-SHA256:ECDH-ECDSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256&lt;BR /&gt;10-31-2022 14:44:12.321 -0500 INFO MongodRunner [17672 MainThread] - Using mongod command line --noscripting&lt;BR /&gt;10-31-2022 14:44:12.326 -0500 ERROR MongodRunner [17672 MainThread] - Failed to start mongod.&lt;BR /&gt;10-31-2022 14:59:13.939 -0500 ERROR KVStoreConfigurationProvider [17672 MainThread] - Cannot dump kvstore data reason=Failed to receive response from kvstore error=, service not ready after waiting for timeout=901610ms&lt;BR /&gt;10-31-2022 14:59:13.939 -0500 ERROR KVStoreConfigurationProvider [17672 MainThread] - Failed to receive response from kvstore error=, service not ready after waiting for timeout=901610ms&lt;BR /&gt;10-31-2022 15:01:27.887 -0500 INFO LMStackMgr [0 MainThread] - Initializing CleMgr...&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LicenseMgr [0 MainThread] - Initing LicenseMgr&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMConfig [0 MainThread] - serverName=IT-JMODLIN guid=DBE7F1CA-C25F-430E-AB8C-DA68B1792CC4&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMConfig [0 MainThread] - connection_timeout=30&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMConfig [0 MainThread] - send_timeout=30&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMConfig [0 MainThread] - receive_timeout=30&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMConfig [0 MainThread] - key=license_warnings_update_interval not found in licenser stanza of server.conf, defaulting=0&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMConfig [0 MainThread] - squash_threshold=2000&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMConfig [0 MainThread] - strict_pool_quota=1&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMConfig [0 MainThread] - key=pool_suggestion not found in licenser stanza of server.conf, defaulting=''&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMConfig [0 MainThread] - key=test_aws_metering not found in licenser stanza of server.conf, defaulting=0&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMConfig [0 MainThread] - key=test_aws_product_code not found in licenser stanza of server.conf, defaulting=0&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LicenseMgr [0 MainThread] - Initing LicenseMgr runContext_splunkd=false&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMStackMgr [0 MainThread] - closing stack mgr&lt;BR /&gt;10-31-2022 15:01:27.888 -0500 INFO LMSlaveInfo [0 MainThread] - all slaves cleared&lt;BR /&gt;10-31-2022 15:01:27.889 -0500 INFO LMStackMgr [0 MainThread] - Initalized license_warnings_update_interval=auto&lt;BR /&gt;10-31-2022 15:01:27.889 -0500 INFO LMStackMgr [0 MainThread] - License Manager supports Conditional Licensing Enforcement. For baked in CLE policies, window_period=60 days, max_violations=45, for stack size below 107374182400 bytes&lt;BR /&gt;10-31-2022 15:01:27.889 -0500 INFO LMLicense [0 MainThread] - Applying default enforcement policy for free&lt;BR /&gt;10-31-2022 15:01:27.889 -0500 INFO LMStackMgr [0 MainThread] - Added policy WinSz=30 Warnings=3 MaxSize=0 isDefault=1 features= for free&lt;BR /&gt;10-31-2022 15:01:27.889 -0500 INFO LMLicense [0 MainThread] - Applying default enforcement policy for forwarder&lt;BR /&gt;10-31-2022 15:01:27.889 -0500 INFO LMStackMgr [0 MainThread] - Added policy WinSz=30 Warnings=5 MaxSize=0 isDefault=1 features= for forwarder&lt;BR /&gt;10-31-2022 15:01:27.891 -0500 INFO LMStack [0 MainThread] - Added type=forwarder license, from file=splunkforwarder.lic, to stack=forwarder of group=Forwarder&lt;BR /&gt;10-31-2022 15:01:27.891 -0500 INFO LMLicense [0 MainThread] - Applying default enforcement policy for forwarder&lt;BR /&gt;10-31-2022 15:01:27.891 -0500 INFO LMStackMgr [0 MainThread] - created stack='forwarder'&lt;BR /&gt;10-31-2022 15:01:27.891 -0500 INFO LMStackMgr [0 MainThread] - Replaced with latest policy WinSz=30 Warnings=5 MaxSize=0 isDefault=1 features= for forwarder&lt;BR /&gt;10-31-2022 15:01:27.891 -0500 INFO LMStackMgr [0 MainThread] - Initialized hideQuotaWarning = "0"&lt;BR /&gt;10-31-2022 15:01:27.891 -0500 INFO LMStackMgr [0 MainThread] - init completed [DBE7F1CA-C25F-430E-AB8C-DA68B1792CC4,Forwarder,runContext_splunkd=false]&lt;BR /&gt;10-31-2022 15:01:27.891 -0500 INFO LicenseMgr [0 MainThread] - StackMgr init complete...&lt;BR /&gt;10-31-2022 15:01:27.891 -0500 INFO LMTracker [0 MainThread] - Setting default product type='enterprise'&lt;BR /&gt;10-31-2022 15:01:27.892 -0500 INFO LMTracker [0 MainThread] - this is not splunkd, will perform partial init&lt;BR /&gt;10-31-2022 15:01:27.892 -0500 INFO LicenseMgr [0 MainThread] - Tracker init complete...&lt;BR /&gt;10-31-2022 15:01:27.899 -0500 INFO KVStorageEngineUpgrade [0 MainThread] - Setting parallelDumpCollectionJobs=0 parallelRestoreCollectionJobs=0 based on max_num_cpus=8 and total_configured_collections=0, insertionWorkersPerCollection=1 as maxInsertionWorkersPerCollection=4&lt;BR /&gt;10-31-2022 15:01:27.906 -0500 INFO KVStoreBackupRestore [0 MainThread] - Before KV Store engine migration: KVStoreDbsize=4096 fsBytesFree=90669641728&lt;BR /&gt;10-31-2022 15:01:27.907 -0500 WARN SSLOptions [17024 MainThread] - server.conf/[kvstore]/sslVerifyServerCert is false disabling certificate validation; must be set to "true" for increased security&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Starting mongod with executable name=mongod.exe version=kvstore version 4.2&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --dbpath C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\kvstore\mongo&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --storageEngine wiredTiger&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using cacheSize=2.25GB&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --port 8191&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --timeStampFormat iso8601-utc&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --oplogSize 200&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --keyFile C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\kvstore\mongo\splunk.key&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --setParameter enableLocalhostAuthBypass=0&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --setParameter oplogFetcherSteadyStateMaxFetcherRestarts=0&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Starting mongod in standalone mode&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --bind_ip=0.0.0.0 (all ipv4 addresses)&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --sslMode requireSSL&lt;BR /&gt;10-31-2022 15:01:27.911 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --sslAllowInvalidHostnames&lt;BR /&gt;10-31-2022 15:01:28.152 -0500 INFO MongodRunner [17024 MainThread] - Found an existing PFX certificate&lt;BR /&gt;10-31-2022 15:01:28.152 -0500 INFO MongodRunner [17024 MainThread] - Found an existing PFX certificate&lt;BR /&gt;10-31-2022 15:01:28.152 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --sslCertificateSelector subject=SplunkServerDefaultCert&lt;BR /&gt;10-31-2022 15:01:28.152 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --sslAllowInvalidCertificates&lt;BR /&gt;10-31-2022 15:01:28.152 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --sslAllowConnectionsWithoutCertificates&lt;BR /&gt;10-31-2022 15:01:28.152 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --tlsDisabledProtocols noTLS1_0,noTLS1_1&lt;BR /&gt;10-31-2022 15:01:28.152 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --sslCipherConfig ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128-GCM-SHA256:ECDH-ECDSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256&lt;BR /&gt;10-31-2022 15:01:28.152 -0500 INFO MongodRunner [17024 MainThread] - Using mongod command line --noscripting&lt;BR /&gt;10-31-2022 15:01:28.158 -0500 ERROR MongodRunner [17024 MainThread] - Failed to start mongod.&lt;BR /&gt;10-31-2022 15:16:29.657 -0500 ERROR KVStoreConfigurationProvider [17024 MainThread] - Cannot dump kvstore data reason=Failed to receive response from kvstore error=, service not ready after waiting for timeout=901500ms&lt;BR /&gt;10-31-2022 15:16:29.657 -0500 ERROR KVStoreConfigurationProvider [17024 MainThread] - Failed to receive response from kvstore error=, service not ready after waiting for timeout=901500ms&lt;/P&gt;&lt;P&gt;```&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 20:25:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619016#M12048</guid>
      <dc:creator>JacksonModlin</dc:creator>
      <dc:date>2022-10-31T20:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder Install with powershell</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619022#M12049</link>
      <description>&lt;P&gt;I think I wasn't clear earlier.&amp;nbsp; The forwarder for Splunk Cloud is *exactly* the same as the one for Splunk Enterprise.&amp;nbsp; The destination of the data is the only difference.&lt;/P&gt;&lt;P&gt;It looks like you're running into a problem I've seen others report.&amp;nbsp; The universal forwarder doesn't use KVstore and should not be trying to install mongdb.&amp;nbsp; Try installing an earlier version of the forwarder to get around this until a fix comes out.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 21:09:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619022#M12049</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-31T21:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder Install with powershell</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619025#M12050</link>
      <description>&lt;P&gt;I downloaded version 9.0.0.1, and 8.2.8 and neither worked for our purposes, as both still resulted in mongDB still installing, is there any other guidance, you can provide, or is this the final verdict?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 21:50:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619025#M12050</guid>
      <dc:creator>JacksonModlin</dc:creator>
      <dc:date>2022-10-31T21:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder Install with powershell</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619029#M12051</link>
      <description>&lt;P&gt;You can try disabling the KVstore by adding these lines to $SPLUNK_HOME/etc/system/local/server.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[kvstore]
disabled=true&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 01 Nov 2022 00:41:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619029#M12051</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-01T00:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder Install with powershell</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619118#M12052</link>
      <description>&lt;P&gt;I try that, and it still fails to install, i have started to log the file for installing, and the error is below, i have censored out sensitive data.&lt;/P&gt;&lt;P&gt;MSI (s) (98:C0) [09:20:28:480]: Note: 1: 1708&lt;BR /&gt;MSI (s) (98:C0) [09:20:28:480]: Note: 1: 2205 2: 3: Error&lt;BR /&gt;MSI (s) (98:C0) [09:20:28:480]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1708&lt;BR /&gt;MSI (s) (98:C0) [09:20:28:480]: Note: 1: 2205 2: 3: Error&lt;BR /&gt;MSI (s) (98:C0) [09:20:28:480]: Note: 1: 2228 2: 3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1709&lt;BR /&gt;MSI (s) (98:C0) [09:20:28:480]: Product: UniversalForwarder -- Installation failed.&lt;/P&gt;&lt;P&gt;MSI (s) (98:C0) [09:20:28:481]: Windows Installer installed the product. Product Name: UniversalForwarder. Product Version: 9.0.1.0. Product Language: 1033. Manufacturer: Splunk, Inc.. Installation success or error status: 1603.&lt;/P&gt;&lt;P&gt;MSI (s) (98:C0) [09:20:28:494]: Deferring clean up of packages/files, if any exist&lt;BR /&gt;MSI (s) (98:C0) [09:20:28:494]: MainEngineThread is returning 1603&lt;BR /&gt;MSI (s) (98:00) [09:20:28:494]: No System Restore sequence number for this installation.&lt;BR /&gt;=== Logging stopped: 11/1/2022 9:20:28 ===&lt;BR /&gt;MSI (s) (98:00) [09:20:28:496]: User policy value 'DisableRollback' is 0&lt;BR /&gt;MSI (s) (98:00) [09:20:28:496]: Machine policy value 'DisableRollback' is 0&lt;BR /&gt;MSI (s) (98:00) [09:20:28:496]: Incrementing counter to disable shutdown. Counter after increment: 0&lt;BR /&gt;MSI (s) (98:00) [09:20:28:496]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2&lt;BR /&gt;MSI (s) (98:00) [09:20:28:497]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2&lt;BR /&gt;MSI (s) (98:00) [09:20:28:497]: Decrementing counter to disable shutdown. If counter &amp;gt;= 0, shutdown will be denied. Counter after decrement: -1&lt;BR /&gt;MSI (s) (98:00) [09:20:28:497]: Destroying RemoteAPI object.&lt;BR /&gt;MSI (s) (98:14) [09:20:28:497]: Custom Action Manager thread ending.&lt;BR /&gt;MSI (c) (08:4C) [09:20:28:498]: Decrementing counter to disable shutdown. If counter &amp;gt;= 0, shutdown will be denied. Counter after decrement: -1&lt;BR /&gt;MSI (c) (08:4C) [09:20:28:500]: MainEngineThread is returning 1603&lt;BR /&gt;=== Verbose logging stopped: 11/1/2022 9:20:28 ===&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 14:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619118#M12052</guid>
      <dc:creator>JacksonModlin</dc:creator>
      <dc:date>2022-11-01T14:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder Install with powershell</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619127#M12053</link>
      <description>&lt;P&gt;I suggest requesting help from Splunk support if you can.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 14:50:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-forwarder-with-powershell/m-p/619127#M12053</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-01T14:50:12Z</dc:date>
    </item>
  </channel>
</rss>

