Skip to content

Deploy UniversalForwarder to Microsoft Intune

Published by Splunk in Monitoring

UniversalForwarder

The universal forwarder collects data from a data source or another forwarder and sends it to a forwarder or a Splunk deployment. With a universal forwarder, you can send data to Splunk Enterprise, Splunk Light, or Splunk Cloud.

Publisher
Splunk
License
Proprietary
Category
Monitoring

Deployment details

Latest version
10.4.2
Installer type
msi
Install scope
machine
Silent install arguments
/qn /norestart AGREETOLICENSE=YES ALLUSERS=1
Install command
.\payload\Invoke-AppDeployToolkit.exe
Uninstall command
.\payload\Invoke-AppDeployToolkit.exe -DeploymentType Uninstall
Detection rule
The exact Intune detection rules generated for this PSADT package
App source
win32

Commands and arguments were captured during an automated QA install of version 10.4.2 in an isolated Windows VM.

Tested by IntuneGet QA

Passed

Version 10.4.2 tested on August 22, 2026.

VirusTotal scan of the installer hash: clean. 0 of 75 engines flagged it.

Recent versions

  1. 10.4.2
  2. 10.4.1
  3. 10.4.0
  4. 10.2.3
  5. 10.2.1
  6. 10.2.0

How deployment works

IntuneGet packages UniversalForwarder as a Win32 app and uploads it directly to your Microsoft Intune tenant. You review the package settings, configure assignments, and start the deployment from one guided workflow.

Deploy UniversalForwarder to your tenant

Sign in with your Microsoft work account, choose your apps, and let IntuneGet prepare the deployment.

Start deploying free