Getting Data In

How can I install multiple instances of the universal forwarder?

pfabrizi
Path Finder

My team are the IS Security folks for the company. We are migrating to SPLUNK from McAfee Nitro and currently we only have a need to look at Windows security event logs. We have our business folks using their own deployment of SPLUNK and we don't want to piggy back or share the deployment as this now need to be managed by our operations team and slow down any upgrades we might want to do that business area wouldn't. For these reason we want our own deployment. I have tested running multiple instances on a device by installing, poking the registry to change the service name, zipping up the contents, exporting the registry key then play it back on another device. While this would work with old software deployment strategy it will not work with our new which is puppet.

I can install via puppet using the MSI and while I can deploy to a folder of my choosing the service is still installed as splunkuniversalforwader.

I am looking for suggestions on how I can implement this.

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Theres no way to set the service name using the MSI installer, so the only way is the registry hack you've already figured out.

http://docs.splunk.com/Documentation/Splunk/6.6.3/Installation/InstallonWindowsviathecommandline

You can import registry files with puppet though:

https://stackoverflow.com/questions/39544548/silent-way-to-import-registry-file-via-puppet-module

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

Theres no way to set the service name using the MSI installer, so the only way is the registry hack you've already figured out.

http://docs.splunk.com/Documentation/Splunk/6.6.3/Installation/InstallonWindowsviathecommandline

You can import registry files with puppet though:

https://stackoverflow.com/questions/39544548/silent-way-to-import-registry-file-via-puppet-module

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...