Skip to main content

Deploying the Log Collector Across a Fleet

Installing the Chipper Log Collector one machine at a time is fine for a single instrument PC. When your IT team manages many Windows machines, deploy it the way you deploy everything else — silently, through Intune, SCCM/MECM or Group Policy, with one installer and one shared property set.

The piece that makes this work is a reusable enrollment token: one token that enrolls your whole fleet, so you don't have to mint and embed a unique token per machine.


When to use fleet deployment​

Use fleet deployment if...Use the single-PC install if...
✅ You manage machines with Intune / SCCM / GPO❌ You're setting up one instrument PC → Log Collector
✅ You push one MSI + one property set to many boxes❌ You want the interactive, one-time install
✅ You need silent, unattended, repeatable installs❌ You'll click through the installer by hand

Everything about how the Collector runs — the service, config, auto-update — is identical to the single-PC install. This guide only covers getting it onto many machines at once. For what to configure once it's installed, see Configure on the Log Collector page.


How fleet enrollment works​

Each machine installs the same MSI with the same ENROLL_CODE. On first boot, every collector redeems that token independently and registers itself as its own collector in Chipper — up to the token's machine limit, or until it expires.


Step 1 — Mint a reusable enrollment token​

Reusable fleet tokens require an Enterprise account and an editor or administrator. Coordinate issuance with Chipper Support before packaging a fleet install. The current log-source wizard creates single-machine tokens; it does not expose a "Multiple machines" enrollment form.

Agree the maximum machine count and rollout window (up to 30 days), then obtain the reusable token and the deployment command for the intended environment. Copy the token when issued; Chipper stores its hash and cannot show the original again. Record the token's identifier so an authorized administrator or Support can revoke it when the rollout is finished.

A reusable token is bounded on purpose

It's valid until either the machine limit or the expiry is reached — whichever comes first. Size the limit to your fleet (a little headroom for re-images is fine) and keep the window only as long as the rollout needs. Mint a fresh one for the next wave. Tokens are revocable by an authorized administrator through the enrollment-token API, and Chipper stores only a hash — copy it when it's shown, because it isn't retrievable later.

A single-use token is the right choice for an interactive one-off install; it enrolls exactly one machine and is capped at 24 hours. Fleet deployment needs the reusable token.


Step 2 — Install silently with MSI properties​

The Collector's enrollment settings are passed as MSI properties on the msiexec command line. The installer persists them to the registry (HKLM\SOFTWARE\Chipper\Collector), and the agent reads them on first boot to enroll.

msiexec /i chipper-collector.msi /quiet /norestart ENROLL_CODE=enr_your-reusable-token

On a non-production environment, include the API host so the fleet enrolls against the right environment instead of production:

msiexec /i chipper-collector.msi /quiet /norestart FIBER_URL=https://your-env-api.chipper.bio ENROLL_CODE=enr_your-reusable-token

MSI properties​

PropertyRequiredDefaultPurpose
ENROLL_CODEYes(none)The enrollment token the collector redeems on first boot. Use your reusable token here. Treated as secret — it isn't echoed in the install UI.
FIBER_URLNohttps://api.chipper.bioThe Chipper API the collector enrolls against. Omit on production; set it for dev/staging environments.
Copy the exact command from Chipper

The enrollment handoff supplies a ready-to-run command with ENROLL_CODE already filled in (and FIBER_URL on non-prod). Copy that rather than hand-typing the token — it's long and easy to mistype.

Treat the deployment command as a secret

ENROLL_CODE is passed on the msiexec command line, which Windows and your management tooling (Intune/SCCM/GPO) may capture in install logs and process history. Restrict who can read those logs, and have the token revoked through your administrator or Chipper Support once the rollout is complete (or mint a short-expiry token sized to the rollout window). Anyone who obtains a still-valid token can enroll a collector until it expires or is exhausted.

Silent-install flags​

FlagMeaning
/iInstall
/quietNo UI, no prompts (unattended) — same as /qn
/norestartDon't reboot the machine, even if the installer would otherwise ask
/l*v log.txtWrite a verbose install log (useful when debugging a failed deployment)
/xUninstall (see below)

Deploy via Intune​

Package the MSI as a Win32 app (.intunewin via the Microsoft Win32 Content Prep Tool) so you can pass the ENROLL_CODE property — the plain "Line-of-business app" MSI type doesn't let you supply custom properties.

  • Install command:
    msiexec /i chipper-collector.msi /quiet /norestart ENROLL_CODE=enr_your-reusable-token
  • Uninstall command:
    msiexec /x chipper-collector.msi /quiet /norestart
  • Install behavior: System
  • Detection rule: use the MSI product code — Intune auto-detects it from the packaged MSI, and it's the native option. (Intune's built-in rule types are MSI product code, file, or registry; there's no "service exists" rule, so detecting the ChipperLogCollector service instead requires a custom detection script.)

Assign the app to your device group; Intune installs it silently on next check-in.


Deploy via SCCM / MECM​

Create an Application with a Windows Installer (*.msi) deployment type, then override the installation program to include the property:

  • Installation program:
    msiexec /i chipper-collector.msi /quiet /norestart ENROLL_CODE=enr_your-reusable-token
  • Uninstall program:
    msiexec /x chipper-collector.msi /quiet /norestart
  • Detection method: the MSI product code (the native option), or a custom script that checks for the ChipperLogCollector service.
  • Install behavior: Install for system.

Deploy to a device collection as Required for a hands-off rollout.


Deploy via Group Policy (GPO)​

GPO Software Installation publishes an MSI but can't pass properties directly — use one of:

  • Startup script (recommended): a computer Startup PowerShell/batch script that runs the msiexec command with ENROLL_CODE, guarded so it only installs once:
    if (-not (Get-Service ChipperLogCollector -ErrorAction SilentlyContinue)) {
    Start-Process msiexec.exe -Wait -ArgumentList `
    '/i', '\\fileserver\share\chipper-collector.msi', '/quiet', '/norestart', `
    'ENROLL_CODE=enr_your-reusable-token'
    }
  • MST transform: author a transform (.mst) that sets ENROLL_CODE/FIBER_URL and attach it to a GPO Software Installation package.

Place the MSI on a share every target machine can read, and confirm outbound HTTPS to the API host is allowed.


Application allowlisting (AppLocker / WDAC)​

If your environment blocks unapproved installers, allowlist the Collector:

  • By file hash: compute the exact installer's SHA-256 and allow that hash. Refresh it when adopting a different build.
    Get-FileHash chipper-collector.msi -Algorithm SHA256
  • By publisher: use this only after verifying the downloaded MSI has a valid Authenticode signature and confirming the expected publisher with Support. Do not infer signing status from an old release note or from the filename.
    Get-AuthenticodeSignature chipper-collector.msi

Coordinate allowlisting with automatic updates from downloads.chipper.bio so a later installer is not blocked. Ask Support for the current release's publisher and hash where needed.


Verify the rollout​

  1. Per machine: Get-Service ChipperLogCollector reports Running.
  2. Across the fleet: each enrolled machine appears in Chipper's collector fleet view, with its hostname and last-seen time.
  3. Have your administrator or Support check the token's usage through the enrollment-token API. When the machine limit is reached or the token expires, further installs need a new token.

Enrollment alone does not select the instrument logs. Bind each collector to its instrument sources and configure local include patterns through the log-source wizard. Standalone deployments also need the customer-storage sink configured locally. See Configure.


Uninstall at scale​

Silently, per machine:

msiexec /x chipper-collector.msi /quiet /norestart

Through your management tool, run the same command as the app's uninstall action (Intune uninstall command, SCCM uninstall program, or a GPO removal). Have your administrator or Chipper Support revoke any still-valid enrollment token afterwards.


Troubleshooting​

A machine installed but never appeared in Chipper​

  • Token exhausted or expired: if the rollout outgrew the token's machine limit or ran past its expiry, later machines can't enroll. Mint a fresh reusable token and re-run the install on the affected boxes.
  • Wrong environment: confirm FIBER_URL (or the production default) points at the API you're checking. The persisted values live under HKLM\SOFTWARE\Chipper\Collector.
  • Network: the machine needs outbound HTTPS to the API host to enroll.
  • Logs: the agent writes to C:\ProgramData\Chipper\Collector\logs\.

The install itself failed​

  • Re-run with a verbose log and inspect it: msiexec /i chipper-collector.msi /quiet /l*v install-log.txt ENROLL_CODE=enr_your-reusable-token.
  • If an allowlist is blocking the MSI, see Application allowlisting.

Need help?​

  • Machines not enrolling? Check the token isn't exhausted/expired and that FIBER_URL is correct.
  • Installer blocked? Ask support for the current publisher/hash for your allowlist.
  • Other questions? Contact support.