Getting Data In

Does outputs.conf get created when installing from CLI?

benjaminmeyers
Engager

Hi All,

I'm trying to install the Universal Forwarder via Command Line but I am running into some issues.

Version: splunkforwarder-6.1.1-207789-x64-release.msi

The issue that I'm running into is that the outputs.conf file is not getting created in c:/program files/splunkuniversalforwarder/etc/system/local.

The command line I'm using is:
msiexec.exe /i splunkforwarder-6.1.1-207789-x64-release.msi RECEIVING_INDEXER=”server_name:9997” WINEVENTLOG_APP_ENABLE=1 WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 WINEVENTLOG_FWD_ENABLE=1 WINEVENTLOG_SET_ENABLE=1 PERFMON=cpu,memory,network,diskspace ENABLEADMON=1 AGREETOLICENSE=Yes /quiet

So my question I guess is, is this expected from installing via command line or is this not normal?

I have tested multiple versions of this command line string removing and changing various flags but it hasn't made a difference. I have noticed though that if I install via the installation wizard the outputs.conf file does get created. Any suggestions are welcomed and appreciated!

Thanks!

Tags (3)
0 Karma
1 Solution

mstegmueller
Explorer

in linux for example, the outputs.conf file is never created. it would be empty anyway. so just create it after the installation and restart the splunk service.

BR
Markus

View solution in original post

mstegmueller
Explorer

in linux for example, the outputs.conf file is never created. it would be empty anyway. so just create it after the installation and restart the splunk service.

BR
Markus

benjaminmeyers
Engager

I appreciate your response Markus... I was thinking that this would be the way it is, but hoping at the same time that it wasn't.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...