Hello All,
Does anyone know of an efficient method to deploy Splunk UF v6.3.3 with Splunk_TA_Windows to several hundred Windows 2012 Servers? I've search the web but there were nothing about 2012 servers and Splunk UF v6.3.3 with Splunk_TA_Windows.
Thanks!
I would use a Deployment Server for that as follows:
Install the universal forwarder to run as the Local System user and request configuration from deploymentserver1, automatically agree to license and install in silent mode
msiexec.exe /i splunkuniversalforwarder_x86.msi DEPLOYMENT_SERVER="deploymentserver1:8089" AGREETOLICENSE=Yes /quiet
If you want to use a domain user the syntax is different. More info here
Your UF will contact the deployment server and download any app made available to it based on your whitelist and blacklist configurations in your serverclass.conf
Hope that helps,
J
I would use a Deployment Server for that as follows:
Install the universal forwarder to run as the Local System user and request configuration from deploymentserver1, automatically agree to license and install in silent mode
msiexec.exe /i splunkuniversalforwarder_x86.msi DEPLOYMENT_SERVER="deploymentserver1:8089" AGREETOLICENSE=Yes /quiet
If you want to use a domain user the syntax is different. More info here
Your UF will contact the deployment server and download any app made available to it based on your whitelist and blacklist configurations in your serverclass.conf
Hope that helps,
J
Thank you J. This helped and worked.
This was our command using (psexec):
msiexec.exe /i splunkforwarder-6.3.3-f44afce176d0-x64-release.msi DEPLOYMENT_SERVER="deployerip:8089" RECEIVING_INDEXER="indexerhostname.com:9997" WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 AGREETOLICENSE=Yes /quiet
We were also able to enable winevent at the same time.