Installation

Why is my install command corrupting my installs (25+ times)?

aborgeld
Explorer

Hello

For my SCCM deployment I use the following MSI install command:
msiexec.exe /i splunkforwarder-6.3.3-x64-release.msi RECEIVING_INDEXER="IndexServ:9997" DEPLOYMENT_SERVER="DPServ:8089" WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 AGREETOLICENSE=Yes /q

This works fine in most cases where an installation was successful but in some cases I get a corrupt installation back.
I get the message that the universal forwarder was already installed but I see no Control Panel (add remove programs) option.
Sometimes there is still a directory you need to remove and sometimes there is a value in the HKCR -> Installer -> Products/Features.
For one server this isn't a problem, but it happened on 25 servers. So I have two question with a new Universal Forwarder update:

1) Is there a force install option so the application always gets installed?
2) Will I get the same message when I upgrade and how to solve this on multiple servers?

Kind regards,

André

Labels (1)
0 Karma
1 Solution

aborgeld
Explorer

Hi everyone,

6.3.3. cannot be used in combination with SCCM. It has a bug. We are going to 6.3.4.

View solution in original post

0 Karma

aborgeld
Explorer

Hi everyone,

6.3.3. cannot be used in combination with SCCM. It has a bug. We are going to 6.3.4.

View solution in original post

0 Karma

ddrillic
Ultra Champion

Btw, splunkforwarder-6.3.3... seems to be a bit old...

0 Karma

aborgeld
Explorer

Yes, but when you look at ask questions then you see this bug comming back in different versions. And yes i want to upgrade in november 2017 but then i want a work around or a solution.

0 Karma

aborgeld
Explorer

Hey @lfedak_splunk,

Not still not solved. It is a typical bug on Windows deployment, but i'm in contact with SPLUNK so i will write down the answer as soon as we have one.

Kind regards,

André

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Thanks for the update!

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @aborgeld, were you able to figure out this problem? If so we would love to see your solution and you can receive karma points if you accept your own answer. Happy Splunking!

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!