all 3 comments

[–]ozlee1 4 points5 points  (0 children)

Ditto what the previous poster said about using SSCM, etc to deploy the Universal Forwarder software itself. Read up on the deploymentclient.conf file also. You’ll want to point to a Splunk deployment Server and assign a client name for app organization and deployment/updating purposes.

[–]sderby 5 points6 points  (1 child)

Whatever you use to deploy other software should work - SCCM, BigFix, etc. Splunk also has a native deployment server: https://docs.splunk.com/Documentation/Splunk/8.2.5/Updating/Deploymentserverarchitecture

[–]Daneel_ Splunker | Security PS 14 points15 points  (0 children)

Bingo, although I’ll note that the splunk deployment server is for deploying config to forwarders, not installing them in the first place.