Getting Data In

Windows V6 forwarder - no silent install?

sberg
Explorer

It appears as though there is no way to include the "Splunk technology add-on for windows" during a silent install of the v6 universal forwarder. Doing a silent install without this add-on throws the following error in splunkd log....

11-27-2013 12:47:49.171 -0500 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"" splunk-netmon - NetmonConfig::InitNetmonConfig: No valid stanzas found.

Manual installation work fine and creates the typical MSICreated inputs.conf in the tech add-on folder instead.

0 Karma

delink
Communicator

If you install the Splunk universal forwarder using the MSI with a line such as the following:


msiexec.exe /i "%SPLUNK_MSI%" LAUNCHSPLUNK=0 AGREETOLICENSE=Yes /quiet

You can then have a script to copy in any pre-configured apps you'd like to use for the install. I usually use this method to copy in an app containing a deploymentclient.conf configuration file, which then allows the forwarder to receive all of its configuration from the deployment server, including the Splunk_TA_windows app to collect the built-in Windows event logs.

0 Karma

sberg
Explorer

Thanks delink, good information to be aware of. Unfortunately this doesn't help our deployment setup. We manage our forwarder deploys via puppet, and the silent install option would be perfect except for this one issue.

Seems like a significant oversight by the splunk folks, where this add-on is mandatory in the installation.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...