- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to deploy a Splunk Universal Forwarder through GPO and MST setup?

I have been trying to push the Splunk Universal Forwarder out to my client systems via GPO. I would like, however, to generate an MST file that:
a) Accepts the EULA and
b) sets a predefined Receiving Indexer.
Utilizing Orca.exe I have made attempts at MSTs with the following:
Under the Property Table I assigned the Property of AGREETOLICENSE the value of Yes. As for the receiving indexer, I tried both the following:
1) Create new row in the Property table called RECEIVING_INDEXER and set the value to ipaddress:portnumber and
2) Under the AdminProperties row I modified ;RECEIVING_INDEXER; to ;RECEIVING_INDEXER=ipaddress:portnumber neither of which seemed to work.
I also made sure to go to the advanced properties on my GPO to check "Ignore language when deploying this package".
Any and all help would be greatly appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it works?
Could you send me the script?
Thank you!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Try RECEIVING_INDEXER="ipaddress:portnumber"
.
I found when I was testing deploying it via SCCM that the quotes were important.
