I have it working at now, install and then once it reports to the deployment server it updates and brings down the correct stanza.
I have this question and don't know if it should be in a separate thread.
We have multiple deployments of SPLUNK in our company. We have the need to collect security events while the other deployments are collection application logs. We would like to install a separate instance of the universal forwarder in a separate folder with a service name matching the folder. I can do this by installing locally, zipping up the install, then unzip and reg poke the service configuration, but since I am using puppet and our SED folks will not allow a zip and power shell script to do this I need to use the MSI.
Is this possible?
Thanks!
... View more