Installation

Why is my install command corrupting my installs (25+ times)?

aborgeld
Explorer

Hello

For my SCCM deployment I use the following MSI install command:
msiexec.exe /i splunkforwarder-6.3.3-x64-release.msi RECEIVING_INDEXER="IndexServ:9997" DEPLOYMENT_SERVER="DPServ:8089" WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 AGREETOLICENSE=Yes /q

This works fine in most cases where an installation was successful but in some cases I get a corrupt installation back.
I get the message that the universal forwarder was already installed but I see no Control Panel (add remove programs) option.
Sometimes there is still a directory you need to remove and sometimes there is a value in the HKCR -> Installer -> Products/Features.
For one server this isn't a problem, but it happened on 25 servers. So I have two question with a new Universal Forwarder update:

1) Is there a force install option so the application always gets installed?
2) Will I get the same message when I upgrade and how to solve this on multiple servers?

Kind regards,

André

Labels (1)
0 Karma
1 Solution

aborgeld
Explorer

Hi everyone,

6.3.3. cannot be used in combination with SCCM. It has a bug. We are going to 6.3.4.

View solution in original post

0 Karma

aborgeld
Explorer

Hi everyone,

6.3.3. cannot be used in combination with SCCM. It has a bug. We are going to 6.3.4.

0 Karma

ddrillic
Ultra Champion

Btw, splunkforwarder-6.3.3... seems to be a bit old...

0 Karma

aborgeld
Explorer

Yes, but when you look at ask questions then you see this bug comming back in different versions. And yes i want to upgrade in november 2017 but then i want a work around or a solution.

0 Karma

aborgeld
Explorer

Hey @lfedak_splunk,

Not still not solved. It is a typical bug on Windows deployment, but i'm in contact with SPLUNK so i will write down the answer as soon as we have one.

Kind regards,

André

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Thanks for the update!

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @aborgeld, were you able to figure out this problem? If so we would love to see your solution and you can receive karma points if you accept your own answer. Happy Splunking!

0 Karma
Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...