Deployment Architecture

Manual process of Splunk deployment

jangid
Builder

How do I deploy Splunk and SplunkForwarder from zip package instead of msi?

I create a Zip package and trying to run in another machine but I am not able to start it 😞

C:\splunkforwarder\bin>splunk start

Splunk> Take the sh out of IT.

Checking prerequisites...
Checking mgmt port [8090]: open
Checking conf files for typos... Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)... SplunkForwarder: Unable to start the service: The specified service does not exist as an installed service.

I tried to Install service from splunk and standard windows command but I think I am missing something here.

can you guys please help me?

Tags (2)
0 Karma
1 Solution

Splunker
Communicator

Jangid,

The deployment server only deploys/manages Splunk apps/configs, you will need to use something like a GPO/Puppet, etc, to push the actual software.

This is all detailed in the Splunk docs.

View solution in original post

0 Karma

Splunker
Communicator

Jangid,

The deployment server only deploys/manages Splunk apps/configs, you will need to use something like a GPO/Puppet, etc, to push the actual software.

This is all detailed in the Splunk docs.

0 Karma

jangid
Builder

OK I figure out
You need to run below command first time

splunk enable boot-start
after
splunk start

0 Karma

jangid
Builder

My process is very simple, I don't want to push to another server/computer. I just want to use existing pre-configured Splunk forwarder. Something similar to http://wiki.splunk.com/Deploy:Migrating_a_Splunk_Install

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...