Getting Data In

Does outputs.conf get created when installing from CLI?

benjaminmeyers
Engager

Hi All,

I'm trying to install the Universal Forwarder via Command Line but I am running into some issues.

Version: splunkforwarder-6.1.1-207789-x64-release.msi

The issue that I'm running into is that the outputs.conf file is not getting created in c:/program files/splunkuniversalforwarder/etc/system/local.

The command line I'm using is:
msiexec.exe /i splunkforwarder-6.1.1-207789-x64-release.msi RECEIVING_INDEXER=”server_name:9997” WINEVENTLOG_APP_ENABLE=1 WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 WINEVENTLOG_FWD_ENABLE=1 WINEVENTLOG_SET_ENABLE=1 PERFMON=cpu,memory,network,diskspace ENABLEADMON=1 AGREETOLICENSE=Yes /quiet

So my question I guess is, is this expected from installing via command line or is this not normal?

I have tested multiple versions of this command line string removing and changing various flags but it hasn't made a difference. I have noticed though that if I install via the installation wizard the outputs.conf file does get created. Any suggestions are welcomed and appreciated!

Thanks!

Tags (3)
0 Karma
1 Solution

mstegmueller
Explorer

in linux for example, the outputs.conf file is never created. it would be empty anyway. so just create it after the installation and restart the splunk service.

BR
Markus

View solution in original post

mstegmueller
Explorer

in linux for example, the outputs.conf file is never created. it would be empty anyway. so just create it after the installation and restart the splunk service.

BR
Markus

benjaminmeyers
Engager

I appreciate your response Markus... I was thinking that this would be the way it is, but hoping at the same time that it wasn't.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...