Getting Data In

Windows 2008 R2 Core

wwillsey
New Member

Is there a version for Windows Core or instructions to install on Windows Core (No GUI)?

Tags (1)
0 Karma
1 Solution

Michael_Wilde
Splunk Employee
Splunk Employee

If msiexec works at the command line, you should be fine. Docs have info on how to do silent install

http://www.splunk.com/base/Documentation/4.1.3/Installation/InstallonWindowsviathecommandline

Enable SplunkForwarder, disable indexing of the Windows System event log, and run the installer in silent mode

msiexec.exe /i Splunk.msi SPLUNK_APP="SplunkForwarder" FORWARD_SERVER="" WINEVENTLOGSYSCHECK=0 /quiet

View solution in original post

Lowell
Super Champion

Michael_Wilde
Splunk Employee
Splunk Employee

If msiexec works at the command line, you should be fine. Docs have info on how to do silent install

http://www.splunk.com/base/Documentation/4.1.3/Installation/InstallonWindowsviathecommandline

Enable SplunkForwarder, disable indexing of the Windows System event log, and run the installer in silent mode

msiexec.exe /i Splunk.msi SPLUNK_APP="SplunkForwarder" FORWARD_SERVER="" WINEVENTLOGSYSCHECK=0 /quiet

jxjackso
Explorer

I don't know of any off the top of my head...

Only thing i can think of is install on a regular windows 2008 r2 box, then copy the program files over to the core box. You would then need to monkey in the registry of the core box to get the splunk services set up.

Not something for the faint of heart I'm afraid. Although, since they support linux, it would make sense for them to make a version that can be installed through command prompt only means.

0 Karma

jrodman
Splunk Employee
Splunk Employee

If copying the files from one box to another, the command 'splunk enable boot-start' will try to create the services entries to manage the splunk instance.

0 Karma

jxjackso
Explorer

Sorry to reply to my own comment, but check out:

http://www.splunk.com/wiki/Deploy:SplunkForwarder_for_Windows_installscript

It's a script that automates the install of splunk as a forwarder. You may be able to use this as a starting point.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...