I want to use silent instillation of splunk forwarder on a windows server.
The splunk server architecture is : 3 indexers and 1 deployment server which is also the head search .
How do i use silent installation to install the forwarder + tell it to work with deployment server (i guess the indexers are not relevant in the installation) + configure inputs.conf so it will index the logs i need on the server with the required sourcetype.
Any idea ?
Have you configured different deployment classes for both indexers and forwarders?
If so you might want to check your regex in the server class whitelisting to make sure its not pushing the wrong applications
this is how you do the unattended install:
set src=%~dp0 start /wait msiexec /i %src%source\splunkforwarder-6.1.3-220630-x64-release.msi AGREETOLICENSE="yes" /lv* %temp%\splunkforwarder-6.1.3-220630-x64-release.msi.log /qb-
after that set the admin password and deployment server:
splunk edit user admin -password Splunky -auth admin:changeme splunk set deploy-poll mydsserver:8089
then deploy an app configuring inputs.conf and outputs.conf
same for the indexer. deploy splunk.msi and use forwarder-mangement to configure inputs.conf, indexes.conf etc.
can you please elaborate more about the command? what is the meaning of each variable and when do i need to fill the details according to my own splunk architecture?
maybe an example with explanation can be great ! 🙂