Installation

Why is my install command corrupting my installs (25+ times)?

aborgeld
Explorer

Hello

For my SCCM deployment I use the following MSI install command:
msiexec.exe /i splunkforwarder-6.3.3-x64-release.msi RECEIVING_INDEXER="IndexServ:9997" DEPLOYMENT_SERVER="DPServ:8089" WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 AGREETOLICENSE=Yes /q

This works fine in most cases where an installation was successful but in some cases I get a corrupt installation back.
I get the message that the universal forwarder was already installed but I see no Control Panel (add remove programs) option.
Sometimes there is still a directory you need to remove and sometimes there is a value in the HKCR -> Installer -> Products/Features.
For one server this isn't a problem, but it happened on 25 servers. So I have two question with a new Universal Forwarder update:

1) Is there a force install option so the application always gets installed?
2) Will I get the same message when I upgrade and how to solve this on multiple servers?

Kind regards,

André

Labels (1)
0 Karma
1 Solution

aborgeld
Explorer

Hi everyone,

6.3.3. cannot be used in combination with SCCM. It has a bug. We are going to 6.3.4.

View solution in original post

0 Karma

aborgeld
Explorer

Hi everyone,

6.3.3. cannot be used in combination with SCCM. It has a bug. We are going to 6.3.4.

0 Karma

ddrillic
Ultra Champion

Btw, splunkforwarder-6.3.3... seems to be a bit old...

0 Karma

aborgeld
Explorer

Yes, but when you look at ask questions then you see this bug comming back in different versions. And yes i want to upgrade in november 2017 but then i want a work around or a solution.

0 Karma

aborgeld
Explorer

Hey @lfedak_splunk,

Not still not solved. It is a typical bug on Windows deployment, but i'm in contact with SPLUNK so i will write down the answer as soon as we have one.

Kind regards,

André

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Thanks for the update!

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @aborgeld, were you able to figure out this problem? If so we would love to see your solution and you can receive karma points if you accept your own answer. Happy Splunking!

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...