-
-
-
Installing the Windows Endpoint Agent
-
-
-
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Installing the Windows Endpoint Agent
The agent installer is available as an MSI package. The MSI can either be installed manually or unattended through existing software deployment tools or Splunk’s Deployment Server.
Manual Installation
- Run the batch file
uberAgent_endpoint\bin\manual-install.cmd
. - On the screen Receiver Configuration specify the name(s) of your Splunk indexer(s) and the port configured earlier (default: 19500).
Configuration
uberAgent can be configured very flexibly. By editing the configuration you can switch metrics on or off, change the data collection frequency and significantly reduce the data volume.
License File
If you have a license file for uberAgent, copy it to the installation directory (default: C:\Program Files\vast limits\uberAgent
). Without a license file, uberAgent displays a splash screen during logon. Contact us for an evaluation license.
Installation Through a Software Deployment Tool
Install the appropriate MSI file from the directory uberAgent_endpoint\bin
depending on the bitness of your machine: uberAgent-32.msi
or uberAgent-64.msi
.
MSI Parameters
Specify the following MSI parameters:
SERVERS
- Required: yes
- Description: list of target servers/URLs
-
Valid values:
-
TCP input: comma-separated list of
server:port
, e.g.,localhost:19500, splunksrv:12345
-
HEC input: comma-separated list of URLs starting with
http
orhttps
, e.g.,http://server1:8088, https://server2:8088
-
TCP input: comma-separated list of
INSTALLDIR
- Required: no
- Description: installation directory
- Valid values: any local file system path
RECEIVER_PROTOCOL
- Required: no
- Description: how to send data to the backend
-
Valid values:
-
TCP
uses a direct TCP connection. This is the default. -
HTTP
sends to Splunk HTTP Event Collector via HTTP or HTTPS
-
REST_TOKEN
- Required: only when sending to Splunk HTTP Event Collector
- Description: application token required by the Splunk HTTP Event Collector
- Valid values: authentication token created in Splunk
Note: see our documentation on Configuring Splunk’s HTTP Event Collector.
License File
If you have a license file for uberAgent, copy it to the installation directory (default: C:\Program Files\vast limits\uberAgent
). Without a license file, uberAgent displays a splash screen during logon. Contact us for an evaluation license.
Installation Through Splunk Deployment Server
Note: Deployment Server can only be used with Splunk Enterprise and requires Splunk Universal Forwarder on the endpoint as deployment client.
uberAgent
Copy the directory uberAgent_endpoint
from the unzipped uberAgent download package to $SPLUNK_HOME\etc\deployment-apps
on your deployment server.
Edit $SPLUNK_HOME\etc\deployment-apps\uberAgent_endpoint\bin\silent-install.cmd
, modifying the servers
variable so that it contains a list of your Splunk servers. Example:
set servers=splunk1:19500,splunk2:19500
Note: $SPLUNK_HOME
refers to the base directory of the Splunk installation, typically C:\Program Files\Splunk
.
Configuration
To deploy a customized configuration file, copy it into the directory $SPLUNK_HOME\etc\deployment-apps\uberAgent_endpoint\bin
. This overwrites the default configuration file from the installation package.
License File
If you have a license file for uberAgent, copy it into the directory $SPLUNK_HOME\etc\deployment-apps\uberAgent_endpoint\bin
.
Serverclass
Create a file called serverclass.conf
in $SPLUNK_HOME\etc\system\local
on your deployment server. Serverclass.conf
defines what to deploy where. For a quick start paste the following content into Serverclass.conf
to deploy uberAgent to all Windows machines. You may want to fine-tune this to suit your needs.
# [global]
# We cannot match by machine type here. We'll do that on the app level below.
whitelist.0 = *
# Define a serverclass
[serverClass:windows]
# Deploy only to Windows machines
machineTypesFilter = windows-*
# Define which apps to deploy to the serverclass
[serverClass:windows:app:uberAgent_endpoint]
stateOnClient = enabled
restartSplunkd = true
<!--NeedCopy-->
To make Splunk read the new file serverclass.conf
, run the following command:
$SPLUNK_HOME\splunk.exe reload deploy-server
<!--NeedCopy-->
Citrix Site Monitoring
If some or all of your endpoints are running the Citrix Virtual Apps and Desktops (CVAD) VDA, you should install uberAgent on the Citrix delivery controller(s), too. Please see this page for details.
Endpoint to Backend Communication Via Splunk Universal Forwarder
Note: This is optional and not required for the recommended architecture.
If you decided to implement the alternative endpoint to backend communication path via Splunk Universal Forwarder, you need to install Universal Forwarder on each endpoint.
Imaging & Citrix PVS
If you intend to copy the agent installation via an imaging method or Citrix PVS, we recommend you remove instance-specific information. To do that, follow these steps right before capturing the image:
- Stop the service
uberAgent
(but leave the start type atautomatic
). - Open an administrative command prompt.
- Run the command:
reg delete "HKLM\SOFTWARE\vast limits\uberAgent" /f /reg:64
. - Prepare the machine for cloning as necessary, but do not reboot.
If you have Splunk Universal Forwarder installed, please follow the steps listed here, too.
Share
Share
This Preview product documentation is Citrix Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Citrix Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Citrix product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.