Deployment Methods
Pick the method that matches how you manage endpoints. Every method installs the same agent; they differ in how properties are supplied.
| Method | Best for | Notes |
|---|---|---|
| Single machine | One-off or testing | GUI run, or a silent command. |
| RMM mass-deploy | Fleets via an RMM | Silent command as SYSTEM, per-client variable mapping. |
| Datto RMM | Datto RMM | Site id (CS_PROFILE_UID), token from a global variable with a site override. |
| ImmyBot | ImmyBot | Two install rules. Tenant slug is the client id. Service detection. |
| NinjaOne | NinjaOne | Org env vars (NINJA_ORGANIZATION_ID), SYSTEM script, service detection. |
| Group Policy (GPO) | AD-joined Windows | MSI only, properties go in an MST transform. One MST per client. |
| Microsoft Intune | Intune-managed Windows | Win32 app, install command, service-based detection. One app per client tenant. |
| CLI / scripted | Automation | One PowerShell snippet that downloads, verifies, and installs. |
Before you start
- Confirm endpoints meet the minimum system requirements.
- Choose your deployment scope so you know which properties to pass.
- Download and verify the installer, and keep the expected SHA-256 handy.
With Group Policy and Intune, the registration token and client identifiers bind when you build the package (the MST transform or the Win32 app), not per endpoint. Build one package per destination organization (for most MSPs, a client).
Prepare a golden image
If you deploy machines from a captured image (golden image, VDI template, lab rebuild), install the agent on the reference machine, clear its enrollment, and generalize Windows before you capture. Each clone then enrolls with its own identity on first boot.
On the reference machine, as an administrator:
- Stop the agent service so nothing writes while you clear state.
- Delete the identity file
C:\Program Files\SparkLogs\Agent\config\identity.json(under yourINSTALLDIRif you installed elsewhere). This is the enrollment that must not be cloned. - Delete the agent data directory
%ProgramData%\SparkLogs\agent. This removes collection checkpoints, buffered data not yet uploaded, and agent logs from the reference machine. Leave the rest of%ProgramData%\SparkLogsalone so Event Viewer keeps rendering the agent's events. - Keep
C:\Program Files\SparkLogs\Agent\config\bootstrap.yaml, and confirm its registration token is still valid. That file is what lets each clone enroll on first boot without a technician visit. - Generalize Windows with Sysprep so every clone gets its own Windows machine identity:
sysprep /generalize /oobe /shutdown. Two machines cloned without generalizing are identical to any system that reads Windows machine identity, ours included. Microsoft's Sysprep (generalize) a Windows installation covers the full procedure, the rearm limit, and what Sysprep does not support. - Capture the image once the machine has shut itself down.
Stop-Service SparkLogsAgent
Remove-Item 'C:\Program Files\SparkLogs\Agent\config\identity.json' -Force -ErrorAction SilentlyContinue
Remove-Item "$env:ProgramData\SparkLogs\agent" -Recurse -Force -ErrorAction SilentlyContinue
# ######## when you are ready to generalize, shutdown, and capture the system image
& "$env:WINDIR\System32\Sysprep\sysprep.exe" /generalize /oobe /shutdown
Deploy the image as usual. Each machine registers itself the first time it boots.
An image cloned with its enrollment intact is detected and each machine is separated onto its own identity automatically. Preparing the image is simply cleaner: every clone enrolls with its own identity from first boot instead of being separated afterward. See Agent identity and cloning.
Accepting the license
Every silent command includes EULA=ACCEPT, which accepts the
SparkLogs Agent license. The interactive GUI installer prompts for the
license instead.