<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble installing Splunk Universal forwarder using CLI install process in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521466#M63578</link>
    <description>&lt;P&gt;When you tried without the /quiet It returned you a successful installation from the Splunk installer window?&lt;/P&gt;&lt;P&gt;Also, could you please provide more information about OS version? Is it 32 or 64 bits?&lt;/P&gt;</description>
    <pubDate>Fri, 25 Sep 2020 14:22:13 GMT</pubDate>
    <dc:creator>alonsocaio</dc:creator>
    <dc:date>2020-09-25T14:22:13Z</dc:date>
    <item>
      <title>Trouble installing Splunk Universal forwarder using CLI install process</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521385#M63568</link>
      <description>&lt;P&gt;I am trying to install Splunk Universal forwarder using CLI Install process. But, it doesn’t seem to install the software. Below is the command line I am using to install:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;msiexec.exe /i splunkforwarder-8.0.2.1-f002026bad55-x64-release.msi /l*v install_splunkforwarder-x64-release.msi.log SPLUNKUSERNAME="username" SPLUNKPASSWORD="password" AGREETOLICENSE=Yes RECEIVING_INDEXER="SOME_INDEXER:PORT" WINEVENTLOG_APP_ENABLE=1 WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 WINEVENTLOG_FWD_ENABLE=1 WINEVENT_SET_ENABLE=1 /quiet&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if there is anything wrong with the script. Log indicates that the install is successful, but I dont see the software installed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 00:29:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521385#M63568</guid>
      <dc:creator>anandgattu</dc:creator>
      <dc:date>2020-09-25T00:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble installing Splunk Universal forwarder using CLI install process</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521386#M63569</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226732"&gt;@anandgattu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you tried to run the installation without the "/quiet" option? Just to double check there is no error during the process.&lt;/P&gt;&lt;P&gt;I would also check permissions for the user that is running the install command.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 01:16:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521386#M63569</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2020-09-25T01:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble installing Splunk Universal forwarder using CLI install process</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521388#M63570</link>
      <description>&lt;P&gt;just want to ask you to make sure you followed these steps:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mw-headline"&gt;Configure your Windows environment prior to installation&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The following steps are high-level. For step-by-step instructions, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/8.0.6/Installation/PrepareyourWindowsnetworkforaSplunkinstallation" target="_blank" rel="noopener"&gt;Prepare your Windows network for a Splunk Enterprise installation as a network or domain user&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the Splunk Enterprise&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Installation Manual&lt;/I&gt;.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;Create a security group for the user that you want to run the universal forwarder as.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;Add the user you want the universal forwarder to run as to this group.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;(Optional) Set up the universal forwarder user as a managed service account.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;Use the Group Policy Management Console to create and configure Group Policy or Local Security Policy objects for user rights assignments.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;Use the Group Policy Management Console to assign appropriate security rights to the universal forwarder user.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;If you use Active Directory, deploy the Group Policy objects with the updated settings.&lt;/DIV&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN class="mw-headline"&gt;Have credentials for the Splunk admin user ready&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When you install the universal forwarder, you must create credentials for the Splunk administrator user. The installer does not create credentials for the user. Think of a user name and password and be ready to supply them when you perform the installation. If you do not supply at least a password during a silent installation, the universal forwarder can install without any users defined, which prevents login. You must then create a user-seed.conf file to fix the problem and restart the forwarder.&lt;/P&gt;&lt;P&gt;See&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/8.0.6/Security/Secureyouradminaccount" target="_blank" rel="noopener"&gt;Create secure administrator credentials&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Securing Splunk&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for more information on how to create credentials for the Splunk administrator account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(PS - i have given around 350+ karma points so far, received badge for that,.. maybe you also should start "Learn, Give Back, Have Fun")&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 01:33:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521388#M63570</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-09-25T01:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble installing Splunk Universal forwarder using CLI install process</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521390#M63571</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226732"&gt;@anandgattu&lt;/a&gt;I have tried running the installation using the command you provided.&lt;/P&gt;&lt;P&gt;Actually my log files have returned some errors and the forwarder was not installed.&lt;/P&gt;&lt;P&gt;In my case, the errors were happening due to password complexity. So, I would also reccomend you to check if you are meeting Splunk security requirements for admin password.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 01:43:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521390#M63571</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2020-09-25T01:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble installing Splunk Universal forwarder using CLI install process</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521396#M63573</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156088"&gt;@alonsocaio&lt;/a&gt;&amp;nbsp; I tried without /quiet, but still the same.&amp;nbsp; And the password I am using meets the password requirements for the admin password.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 03:32:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521396#M63573</guid>
      <dc:creator>anandgattu</dc:creator>
      <dc:date>2020-09-25T03:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble installing Splunk Universal forwarder using CLI install process</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521466#M63578</link>
      <description>&lt;P&gt;When you tried without the /quiet It returned you a successful installation from the Splunk installer window?&lt;/P&gt;&lt;P&gt;Also, could you please provide more information about OS version? Is it 32 or 64 bits?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 14:22:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/521466#M63578</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2020-09-25T14:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble installing Splunk Universal forwarder using CLI install process</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/523571#M63722</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I ran this in verbose mode so I could log the error and got this..&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;MSI (s) (14:B8) [18:54:17:279]: Note: 1: 1708 
MSI (s) (14:B8) [18:54:17:279]: Note: 1: 2205 2:  3: Error 
MSI (s) (14:B8) [18:54:17:279]: Note: 1: 2228 2:  3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1708 
MSI (s) (14:B8) [18:54:17:279]: Note: 1: 2205 2:  3: Error 
MSI (s) (14:B8) [18:54:17:279]: Note: 1: 2228 2:  3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1709 
MSI (s) (14:B8) [18:54:17:279]: Product: UniversalForwarder -- Installation failed.

MSI (s) (14:B8) [18:54:17:279]: Windows Installer installed the product. Product Name: UniversalForwarder. Product Version: 8.0.2.1. Product Language: 1033. Manufacturer: Splunk, Inc.. Installation success or error status: 1603.

MSI (s) (14:B8) [18:54:17:290]: Deferring clean up of packages/files, if any exist
MSI (s) (14:B8) [18:54:17:290]: MainEngineThread is returning 1603
MSI (s) (14:64) [18:54:17:290]: No System Restore sequence number for this installation.
=== Logging stopped: 10/7/2020  18:54:17 ===
MSI (s) (14:64) [18:54:17:293]: User policy value 'DisableRollback' is 0
MSI (s) (14:64) [18:54:17:293]: Machine policy value 'DisableRollback' is 0
MSI (s) (14:64) [18:54:17:293]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (14:64) [18:54:17:294]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2 
MSI (s) (14:64) [18:54:17:294]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2 
MSI (s) (14:64) [18:54:17:294]: Decrementing counter to disable shutdown. If counter &amp;gt;= 0, shutdown will be denied.  Counter after decrement: -1
MSI (s) (14:64) [18:54:17:295]: Destroying RemoteAPI object.
MSI (s) (14:38) [18:54:17:295]: Custom Action Manager thread ending.
MSI (c) (1C:24) [18:54:17:297]: Decrementing counter to disable shutdown. If counter &amp;gt;= 0, shutdown will be denied.  Counter after decrement: -1
MSI (c) (1C:24) [18:54:17:298]: MainEngineThread is returning 1603
=== Verbose logging stopped: 10/7/2020  18:54:17 ===&lt;/LI-CODE&gt;&lt;P&gt;Any idea what this means?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 04:01:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trouble-installing-Splunk-Universal-forwarder-using-CLI-install/m-p/523571#M63722</guid>
      <dc:creator>anandgattu</dc:creator>
      <dc:date>2020-10-08T04:01:54Z</dc:date>
    </item>
  </channel>
</rss>

