Installation

Why is my install command corrupting my installs (25+ times)?

aborgeld
Explorer

Hello

For my SCCM deployment I use the following MSI install command:
msiexec.exe /i splunkforwarder-6.3.3-x64-release.msi RECEIVING_INDEXER="IndexServ:9997" DEPLOYMENT_SERVER="DPServ:8089" WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 AGREETOLICENSE=Yes /q

This works fine in most cases where an installation was successful but in some cases I get a corrupt installation back.
I get the message that the universal forwarder was already installed but I see no Control Panel (add remove programs) option.
Sometimes there is still a directory you need to remove and sometimes there is a value in the HKCR -> Installer -> Products/Features.
For one server this isn't a problem, but it happened on 25 servers. So I have two question with a new Universal Forwarder update:

1) Is there a force install option so the application always gets installed?
2) Will I get the same message when I upgrade and how to solve this on multiple servers?

Kind regards,

André

Labels (1)
0 Karma
1 Solution

aborgeld
Explorer

Hi everyone,

6.3.3. cannot be used in combination with SCCM. It has a bug. We are going to 6.3.4.

View solution in original post

0 Karma

aborgeld
Explorer

Hi everyone,

6.3.3. cannot be used in combination with SCCM. It has a bug. We are going to 6.3.4.

0 Karma

ddrillic
Ultra Champion

Btw, splunkforwarder-6.3.3... seems to be a bit old...

0 Karma

aborgeld
Explorer

Yes, but when you look at ask questions then you see this bug comming back in different versions. And yes i want to upgrade in november 2017 but then i want a work around or a solution.

0 Karma

aborgeld
Explorer

Hey @lfedak_splunk,

Not still not solved. It is a typical bug on Windows deployment, but i'm in contact with SPLUNK so i will write down the answer as soon as we have one.

Kind regards,

André

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Thanks for the update!

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @aborgeld, were you able to figure out this problem? If so we would love to see your solution and you can receive karma points if you accept your own answer. Happy Splunking!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...