Getting Data In

Unable to install Splunk Universal Forwarder on Network drive

santosh_scb
Path Finder

Hi Team,

Currently, I am facing the following issue:

  • I would like to install Splunk UF package (6.5.3) on a Network drive on Windows System.
    Windows Server IP: 10.23.97.2

  • I was able to copy the UF package on the above Windows Server under Installer

  • Have mapped the Network drive path to I:> drive on Local system

\10.23.97.2\Installer\Splunk_UF_6.5.3.msi
- When I double clicked the .msi package, I am getting the message as Unable to install the package as it is not a Local drive.

I can't login to server using Remote desktop.

I am unable to install UF package on this server. Kindly help me on how can I install the UF package.

Does splunk supports Network installation? regards, Santosh

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi santosh_scb,
Splunk setup must be executed on the target machine, you can use a network driver to copy the file on a server but you cannot execute it on the remote server!
This is because Splunk installation starts some processes on the target server, it isn't only a copy of files.

You have only two ways:

  • ask to the server administrator to install Splunk UF,
  • find a different way to take logs (e.g. WMI), but I don't like it!

Ciao.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...