Getting Data In

Does outputs.conf get created when installing from CLI?

benjaminmeyers
Engager

Hi All,

I'm trying to install the Universal Forwarder via Command Line but I am running into some issues.

Version: splunkforwarder-6.1.1-207789-x64-release.msi

The issue that I'm running into is that the outputs.conf file is not getting created in c:/program files/splunkuniversalforwarder/etc/system/local.

The command line I'm using is:
msiexec.exe /i splunkforwarder-6.1.1-207789-x64-release.msi RECEIVING_INDEXER=”server_name:9997” WINEVENTLOG_APP_ENABLE=1 WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 WINEVENTLOG_FWD_ENABLE=1 WINEVENTLOG_SET_ENABLE=1 PERFMON=cpu,memory,network,diskspace ENABLEADMON=1 AGREETOLICENSE=Yes /quiet

So my question I guess is, is this expected from installing via command line or is this not normal?

I have tested multiple versions of this command line string removing and changing various flags but it hasn't made a difference. I have noticed though that if I install via the installation wizard the outputs.conf file does get created. Any suggestions are welcomed and appreciated!

Thanks!

Tags (3)
0 Karma
1 Solution

mstegmueller
Explorer

in linux for example, the outputs.conf file is never created. it would be empty anyway. so just create it after the installation and restart the splunk service.

BR
Markus

View solution in original post

mstegmueller
Explorer

in linux for example, the outputs.conf file is never created. it would be empty anyway. so just create it after the installation and restart the splunk service.

BR
Markus

benjaminmeyers
Engager

I appreciate your response Markus... I was thinking that this would be the way it is, but hoping at the same time that it wasn't.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...