Getting Data In

How to deploy a Splunk Universal Forwarder through GPO and MST setup?

sardinha1
Engager

I have been trying to push the Splunk Universal Forwarder out to my client systems via GPO. I would like, however, to generate an MST file that:
a) Accepts the EULA and
b) sets a predefined Receiving Indexer.

Utilizing Orca.exe I have made attempts at MSTs with the following:

Under the Property Table I assigned the Property of AGREETOLICENSE the value of Yes. As for the receiving indexer, I tried both the following:
1) Create new row in the Property table called RECEIVING_INDEXER and set the value to ipaddress:portnumber and
2) Under the AdminProperties row I modified ;RECEIVING_INDEXER; to ;RECEIVING_INDEXER=ipaddress:portnumber neither of which seemed to work.

I also made sure to go to the advanced properties on my GPO to check "Ignore language when deploying this package".

Any and all help would be greatly appreciated.

tiagomiranda
Explorer

Is it works?
Could you send me the script?

Thank you!

0 Karma

Richfez
SplunkTrust
SplunkTrust

Try RECEIVING_INDEXER="ipaddress:portnumber".

I found when I was testing deploying it via SCCM that the quotes were important.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...