Getting Data In

Splunk Universal Forwarder Deployment with SCCM

asofo
Path Finder

Hello,

We are trying to deploy the Splunk Universal Forwarder using Microsoft SCCM. I can successfully install the MSI from the command line using:

msiexec /i "splunkforwarder-6.3.0-aa7d4b1ccb80-x64-release.msi" AGREETOLICENSE=Yes DEPLOYMENT_SERVER="mydeploymentserver:8089" /quiet

However when our SCCM admin uses the same command in his deployment manager, the installation fails. According to the SCCM log, the error is:

[LOG[Failed to clear product> advertisement, error code> 1603]LOG]!> date="10-29-2015" component="execmgr"> context="" type="3" thread="17300"> file="msiexecution.cpp:264"

I know this is most likely an SCCM issue, but wanted to see if anyone out there has received a similar error or had a similar issue.

Thanks!

0 Karma

shartwell
Explorer

Could be the "/q" switch SCCM adds to packages when it deploys them.
Splunk already has a "/quiet" switch and the two together will prevent SCCM from deploying it.
You'll need to create a batch file which executes the MSI to get around this problem.

bohanlon_splunk
Splunk Employee
Splunk Employee
0 Karma

asofo
Path Finder

I saw that earlier, but the machines are Windows 7 and I checked all permissions. The weird thing is that there weren't any problems with the 6.0.1 version of the Universal Forwarder.

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...