Skip to content

Deploy UniversalForwarder to Microsoft Intune

Published by Splunk in Monitoring

UniversalForwarder

The universal forwarder collects data from a data source or another forwarder and sends it to a forwarder or a Splunk deployment. With a universal forwarder, you can send data to Splunk Enterprise, Splunk Light, or Splunk Cloud.

Publisher
Splunk
License
Proprietary
Category
Monitoring

Deployment details

Latest version
10.6.0.5
Installer type
msi
Install scope
machine
Silent install arguments
/qn /norestart AGREETOLICENSE=YES ALLUSERS=1
Install command
.\payload\Invoke-AppDeployToolkit.exe
Uninstall command
.\payload\Invoke-AppDeployToolkit.exe -DeploymentType Uninstall
Detection rule
The exact Intune detection rules generated for this PSADT package
App source
win32

Commands and arguments were captured during an automated QA install of version 10.6.0.5 in an isolated Windows VM.

Tested by IntuneGet QA

Passed

Version 10.6.0.5 tested on October 2, 2026.

VirusTotal scan of the installer hash: clean. 0 of 56 engines flagged it.

Package provenance

Installer source
download.splunk.com
Installer SHA-256
FA0CB4CE9995EDAED9B9663F284406D00DE8B6C458F4C9C639319D988C5516A0Check on VirusTotal
PSADT version
4.1.8
Packaging commit
60395492a3
Package profile
7C1B69CCB676D872...

IntuneGet verifies the installer SHA-256 before packaging and does not store the installer. The full evidence, including the recorded hash, is in the QA report.

Recent versions

  1. 10.6.0.5
  2. 10.4.4
  3. 10.4.3
  4. 10.4.2
  5. 10.4.1
  6. 10.4.0
  7. 10.2.3
  8. 10.2.1
  9. 10.2.0

How deployment works

IntuneGet packages UniversalForwarder as a Win32 app and uploads it directly to your Microsoft Intune tenant. You review the package settings, configure assignments, and start the deployment from one guided workflow.

Deploy UniversalForwarder to your tenant

Sign in with your Microsoft work account, choose your apps, and let IntuneGet prepare the deployment.

Start deploying free