Skip to main content

Deployment Methods

Pick the method that matches how you manage endpoints. Every method installs the same agent; they differ in how properties are supplied.

MethodBest forNotes
Single machineOne-off or testingGUI run, or a silent command.
RMM mass-deployFleets via an RMMSilent command as SYSTEM, per-client variable mapping.
Datto RMMDatto RMMSite id (CS_PROFILE_UID), token from a global variable with a site override.
ImmyBotImmyBotTwo install rules. Tenant slug is the client id. Service detection.
NinjaOneNinjaOneOrg env vars (NINJA_ORGANIZATION_ID), SYSTEM script, service detection.
Group Policy (GPO)AD-joined WindowsMSI only, properties go in an MST transform. One MST per client.
Microsoft IntuneIntune-managed WindowsWin32 app, install command, service-based detection. One app per client tenant.
CLI / scriptedAutomationOne PowerShell snippet that downloads, verifies, and installs.

Before you start​

  1. Confirm endpoints meet the minimum system requirements.
  2. Choose your deployment scope so you know which properties to pass.
  3. Download and verify the installer, and keep the expected SHA-256 handy.
GPO and Intune bind values at package time

With Group Policy and Intune, the registration token and client identifiers bind when you build the package (the MST transform or the Win32 app), not per endpoint. Build one package per destination organization (for most MSPs, a client).

Prepare a golden image​

If you deploy machines from a captured image (golden image, VDI template, lab rebuild), install the agent on the reference machine, clear its enrollment, and generalize Windows before you capture. Each clone then enrolls with its own identity on first boot.

On the reference machine, as an administrator:

  1. Stop the agent service so nothing writes while you clear state.
  2. Delete the identity file C:\Program Files\SparkLogs\Agent\config\identity.json (under your INSTALLDIR if you installed elsewhere). This is the enrollment that must not be cloned.
  3. Delete the agent data directory %ProgramData%\SparkLogs\agent. This removes collection checkpoints, buffered data not yet uploaded, and agent logs from the reference machine. Leave the rest of %ProgramData%\SparkLogs alone so Event Viewer keeps rendering the agent's events.
  4. Keep C:\Program Files\SparkLogs\Agent\config\bootstrap.yaml, and confirm its registration token is still valid. That file is what lets each clone enroll on first boot without a technician visit.
  5. Generalize Windows with Sysprep so every clone gets its own Windows machine identity: sysprep /generalize /oobe /shutdown. Two machines cloned without generalizing are identical to any system that reads Windows machine identity, ours included. Microsoft's Sysprep (generalize) a Windows installation covers the full procedure, the rearm limit, and what Sysprep does not support.
  6. Capture the image once the machine has shut itself down.
Stop-Service SparkLogsAgent
Remove-Item 'C:\Program Files\SparkLogs\Agent\config\identity.json' -Force -ErrorAction SilentlyContinue
Remove-Item "$env:ProgramData\SparkLogs\agent" -Recurse -Force -ErrorAction SilentlyContinue
# ######## when you are ready to generalize, shutdown, and capture the system image
& "$env:WINDIR\System32\Sysprep\sysprep.exe" /generalize /oobe /shutdown

Deploy the image as usual. Each machine registers itself the first time it boots.

Unprepared images still work

An image cloned with its enrollment intact is detected and each machine is separated onto its own identity automatically. Preparing the image is simply cleaner: every clone enrolls with its own identity from first boot instead of being separated afterward. See Agent identity and cloning.

Accepting the license​

Every silent command includes EULA=ACCEPT, which accepts the SparkLogs Agent license. The interactive GUI installer prompts for the license instead.