<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: installing splunk forwarder using ansible in Installation</title>
    <link>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511022#M6495</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;why you don’t first get the rpm on your local repository, then verify that it’s correct and then install it from your ansible control node? It’s much secure that way. You know what you are installing to servers and you don’t need to open FW or use proxy to get that binary.&amp;nbsp;&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Sun, 26 Jul 2020 16:18:02 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-07-26T16:18:02Z</dc:date>
    <item>
      <title>installing splunk forwarder using ansible</title>
      <link>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511021#M6494</link>
      <description>&lt;P&gt;While installing splunk forwarder 8.0.5 using ansible, it is throwing an error saying the url is not correct. I am using a basic block to install the rpm for it.&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;install&amp;nbsp;splunk&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;yum&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"{{&amp;nbsp;splunk_fwd_url&amp;nbsp;}}"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;state&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;present&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;The URL i am using is&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;A href="https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&amp;amp;platform=linux&amp;amp;version=8.0.5&amp;amp;product=universalforwarder&amp;amp;filename=splunkforwarder-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm" target="_blank" rel="noopener"&gt;https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&amp;amp;platform=linux&amp;amp;version=8.0.5&amp;amp;product=universalforwarder&amp;amp;filename=splunkforwarder-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;I am not sure if this is the correct URL because this use to work fine with the old version (7.0.0) but not in the latest version.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Below is the ansible error for reference&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;fatal: [default]: FAILED! =&amp;gt; {"changed": false, "msg": "Failed to get nevra information from RPM package: &lt;A href="https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&amp;amp;platform=linux&amp;amp;version=8.0.5&amp;amp;product=universalforwarder&amp;amp;filename=splunkforwarder-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm" target="_blank" rel="noopener"&gt;https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&amp;amp;platform=linux&amp;amp;version=8.0.5&amp;amp;product=universalforwarder&amp;amp;filename=splunkforwarder-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm&lt;/A&gt;"}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 26 Jul 2020 15:47:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511021#M6494</guid>
      <dc:creator>gauravmsharma</dc:creator>
      <dc:date>2020-07-26T15:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: installing splunk forwarder using ansible</title>
      <link>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511022#M6495</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;why you don’t first get the rpm on your local repository, then verify that it’s correct and then install it from your ansible control node? It’s much secure that way. You know what you are installing to servers and you don’t need to open FW or use proxy to get that binary.&amp;nbsp;&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jul 2020 16:18:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511022#M6495</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-26T16:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: installing splunk forwarder using ansible</title>
      <link>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511069#M6496</link>
      <description>&lt;P&gt;Splunk is a secure source and i have the code to verify the download. Anyways it still does not address my query, is this URL a Download-ble one ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 07:59:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511069#M6496</guid>
      <dc:creator>gauravmsharma</dc:creator>
      <dc:date>2020-07-27T07:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: installing splunk forwarder using ansible</title>
      <link>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511119#M6497</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The correct URL to the latests UF seems to be:&lt;/P&gt;&lt;LI-CODE lang="java"&gt;'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&amp;amp;platform=linux&amp;amp;version=8.0.5&amp;amp;product=universalforwarder&amp;amp;filename=splunkforwarder-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm&amp;amp;wget=true'&lt;/LI-CODE&gt;&lt;P&gt;For some unknow reason the rest of it has cut/missed on your original question.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 13:30:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511119#M6497</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-27T13:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: installing splunk forwarder using ansible</title>
      <link>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511135#M6498</link>
      <description>&lt;P&gt;Still the same now it gives an error on No package matching&lt;/P&gt;&lt;P&gt;fatal: [default]: FAILED! =&amp;gt; {"changed": false, "msg": "No package matching '&lt;A href="https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&amp;amp;platform=linux&amp;amp;version=8.0.5&amp;amp;product=splunk&amp;amp;filename=splunk-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm&amp;amp;wget=true" target="_blank"&gt;https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&amp;amp;platform=linux&amp;amp;version=8.0.5&amp;amp;product=splunk&amp;amp;filename=splunk-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm&amp;amp;wget=true&lt;/A&gt;' found available, installed or updated", "rc": 126, "results": ["No package matching '&lt;A href="https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&amp;amp;platform=linux&amp;amp;version=8.0.5&amp;amp;product=splunk&amp;amp;filename=splunk-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm&amp;amp;wget=true" target="_blank"&gt;https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&amp;amp;platform=linux&amp;amp;version=8.0.5&amp;amp;product=splunk&amp;amp;filename=splunk-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm&amp;amp;wget=true&lt;/A&gt;' found available, installed or updated"]}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: In this case i tried installing splunk rpm it gave the error same for UF&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 14:30:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511135#M6498</guid>
      <dc:creator>gauravmsharma</dc:creator>
      <dc:date>2020-07-27T14:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: installing splunk forwarder using ansible</title>
      <link>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511176#M6499</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I suppose that this URL need sing on before it works.&lt;/P&gt;&lt;P&gt;Next URLs works without signing or any authentication.&lt;/P&gt;&lt;P&gt;Splunk server can be found e.g. from URL&amp;nbsp;&lt;A href="http://download.splunk.com/products/splunk/releases/7.3.3/linux/splunk-7.3.3-7af3758d0d5e-linux-2.6-x86_64.rpm" target="_blank" rel="noopener"&gt;http://download.splunk.com/products/splunk/releases/7.3.3/linux/splunk-7.3.3-7af3758d0d5e-linux-2.6-x86_64.rpm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And UF can be found here:&lt;/P&gt;&lt;P&gt;&lt;A href="http://download.splunk.com/products/universalforwarder/releases/8.0.5/linux/splunkforwarder-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm" target="_blank" rel="noopener"&gt;http://download.splunk.com/products/universalforwarder/releases/8.0.5/linux/splunkforwarder-8.0.5-a1a6394cc5ae-linux-2.6-x86_64.rpm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 16:17:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511176#M6499</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-27T16:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: installing splunk forwarder using ansible</title>
      <link>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511319#M6501</link>
      <description>&lt;P&gt;Works like a charm. Thanks for help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 12:31:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/511319#M6501</guid>
      <dc:creator>gauravmsharma</dc:creator>
      <dc:date>2020-07-28T12:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: installing splunk forwarder using ansible</title>
      <link>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/676120#M13562</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;#!/bin/bash

########################## FUNC 
function UFYUM(){
cd /tmp
rpm -Uvh --nodeps `curl -s https://www.splunk.com/en_us/download/universal-forwarder.html\?locale\=en_us | grep -oP '"https:.*(?&amp;lt;=download).*x86_64.rpm"' |sed 's/\"//g' | head -n 1`
yum -y install splunkforwarder.x86_64
sleep 5

}

function UFDEB(){
cd /tmp
wget  `curl -s https://www.splunk.com/en_us/download/universal-forwarder.html\?locale\=en_us | grep -oP '"https:.*(?&amp;lt;=download).*amd64.deb"' |sed 's/\"//g' | head -n 1` -O amd64.deb
dpkg -i amd64.deb
sleep 5

}

function UFConf(){

mkdir -p /opt/splunkforwarder/etc/apps/nwl_all_deploymentclient/local/
cd /opt/splunkforwarder/etc/apps/nwl_all_deploymentclient/local/

cat &amp;lt;&amp;lt;EOF&amp;gt; /opt/splunkforwarder/etc/apps/nwl_all_deploymentclient/local/app.conf
[install]
state = enabled

[package]
check_for_updates = false

[ui]
is_visible = false
is_manageable = false
EOF

cat &amp;lt;&amp;lt;EOF&amp;gt; /opt/splunkforwarder/etc/apps/nwl_all_deploymentclient/local/deploymentclient.conf
[deployment-client]
phoneHomeIntervalInSecs = 60
[target-broker:deploymentServer]
targetUri = XXXXXXXXXXXXXXXXXXXXXXX:8089
EOF

cat &amp;lt;&amp;lt;EOF&amp;gt; /opt/splunkforwarder/etc/system/local/user-seed.conf
[user_info]
USERNAME = admin
PASSWORD = XXXXXXXXXXXXXXXXXXXXXXXX
EOF



/opt/splunkforwarder/bin/splunk cmd btool deploymentclient list --debug

/opt/splunkforwarder/bin/splunk start --accept-license
}

######################################################### MAIN 


# Check for RPM package managers
if command -v yum &amp;gt; /dev/null; then
	UFYUM
	UFConf
else
    echo "No YUM package manager found."
fi

# Check for DEB package managers
if command -v dpkg &amp;gt; /dev/null; then
	UFDEB
    UFConf
else
    echo "No DEB package manager found."
fi


 
 
 &lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 06 Mar 2024 18:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/installing-splunk-forwarder-using-ansible/m-p/676120#M13562</guid>
      <dc:creator>RMcCurdyDOTcom</dc:creator>
      <dc:date>2024-03-06T18:08:22Z</dc:date>
    </item>
  </channel>
</rss>

