<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise 9.1.3: Universal Forwarder can't be updated in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675379#M18468</link>
    <description>&lt;P&gt;We have exactly the same problem here. Tested today on a Windows 2016/2019 - UFW Update from 9.1.1 to 9.1.3&lt;/P&gt;&lt;P&gt;But a new installation is out of the question for us, as you will lose all checkpoints&amp;nbsp;and a reread of all is the result.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jan 2024 12:46:44 GMT</pubDate>
    <dc:creator>swaro_ck</dc:creator>
    <dc:date>2024-01-25T12:46:44Z</dc:date>
    <item>
      <title>Splunk Enterprise 9.1.3: Universal Forwarder can't be updated</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675236#M18448</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;today I successfully updated Splunk Enterprise to 9.1.3 (from 9.1.2) on a Windows 10 22H2 Pro machine with the newest Windows updates (January 2024).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Then I wanted to update the Universal Forwarder on this machine, too. Actually, there's 9.1.2 running and everything is working fine. But updating to 9.1.3 doesn't work. Near to the end of the installation process, the installation is rolled back to 9.1.2. Before the rollback there are coming up some more windows for a very short time. And then there are more then one message windows saying, that the installation failed. You then have to click on OK in every message window to finish successfully the rollback.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don't see why the update is failing.&amp;nbsp;&lt;/SPAN&gt;Does anyone have the same issue? And how did you solve this issue?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 23:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675236#M18448</guid>
      <dc:creator>TheExpert</dc:creator>
      <dc:date>2024-01-23T23:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 9.1.3: Universal Forwarder can't be updated</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675237#M18449</link>
      <description>&lt;P&gt;In the Windows event log I can see that some drivers are successfully installed by the update. And then I see these events:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;01/23/2024&lt;/SPAN&gt; &lt;SPAN class=""&gt;11:17:26&lt;/SPAN&gt; &lt;SPAN class=""&gt;PM&lt;/SPAN&gt; &lt;SPAN class=""&gt;LogName=Application&lt;/SPAN&gt; &lt;SPAN class=""&gt;EventCode=11708&lt;/SPAN&gt; &lt;SPAN class=""&gt;EventType=4&lt;/SPAN&gt; &lt;SPAN class=""&gt;ComputerName=&lt;SPAN class=""&gt;WIN10SERVER&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;User=NOT_TRANSLATED&lt;/SPAN&gt; &lt;SPAN class=""&gt;Sid=S-1-5-21-451409098-3557801342-1863680623-1001&lt;/SPAN&gt; &lt;SPAN class=""&gt;SidType=0&lt;/SPAN&gt; &lt;SPAN class=""&gt;SourceName=MsiInstaller&lt;/SPAN&gt; &lt;SPAN class=""&gt;Type=Informationen&lt;/SPAN&gt; &lt;SPAN class=""&gt;RecordNumber=212304&lt;/SPAN&gt; &lt;SPAN class=""&gt;Keywords=Klassisch&lt;/SPAN&gt; &lt;SPAN class=""&gt;TaskCategory=None&lt;/SPAN&gt; &lt;SPAN class=""&gt;OpCode=Info&lt;/SPAN&gt; &lt;SPAN class=""&gt;Message=Product:&lt;/SPAN&gt; &lt;SPAN class=""&gt;UniversalForwarder&lt;/SPAN&gt;&lt;SPAN&gt; -- &lt;/SPAN&gt;&lt;SPAN class=""&gt;Installation&lt;/SPAN&gt; &lt;SPAN class=""&gt;failed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;01/23/2024 11:17:26 PM LogName=Application EventCode=1033 EventType=4 ComputerName=&lt;SPAN class=""&gt;WIN10SERVER&lt;/SPAN&gt; User=NOT_TRANSLATED Sid=S-1-5-21-451409098-3557801342-1863680623-1001 SidType=0 SourceName=MsiInstaller Type=Informationen RecordNumber=212305 Keywords=Klassisch TaskCategory=None OpCode=Info Message=Das Produkt wurde durch Windows Installer installiert. Produktname: UniversalForwarder. Produktversion: 9.1.3.0. Produktsprache: 1033. Hersteller: Splunk&lt;SPAN&gt;, &lt;/SPAN&gt;Inc.. Erfolg- bzw. Fehlerstatus der Installation: 1603.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 23:29:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675237#M18449</guid>
      <dc:creator>TheExpert</dc:creator>
      <dc:date>2024-01-23T23:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 9.1.3: Universal Forwarder can't be updated</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675323#M18458</link>
      <description>&lt;P&gt;Use msiexec /i .... /l*vx logfile.txt&lt;BR /&gt;&lt;BR /&gt;and look for "value 3" in that file. Just above that will show more information about the installation failure.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 00:43:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675323#M18458</guid>
      <dc:creator>wcolgate_splunk</dc:creator>
      <dc:date>2024-01-25T00:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 9.1.3: Universal Forwarder can't be updated</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675326#M18459</link>
      <description>&lt;P&gt;I am also encountering issue when I'm doing a upgrade from 9.1.2.&lt;/P&gt;&lt;P&gt;Coming to the end it will roll back and fail..&lt;/P&gt;&lt;P&gt;A fresh install works fine...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 01:42:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675326#M18459</guid>
      <dc:creator>CheongKing</dc:creator>
      <dc:date>2024-01-25T01:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 9.1.3: Universal Forwarder can't be updated</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675334#M18461</link>
      <description>&lt;P&gt;Thank you. I can confirm that an unistallation of Universal Forwarder 9.1.2 and an installation of Uinversal Forwarder 9.1.3 works without issues.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 07:19:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675334#M18461</guid>
      <dc:creator>TheExpert</dc:creator>
      <dc:date>2024-01-25T07:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 9.1.3: Universal Forwarder can't be updated</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675379#M18468</link>
      <description>&lt;P&gt;We have exactly the same problem here. Tested today on a Windows 2016/2019 - UFW Update from 9.1.1 to 9.1.3&lt;/P&gt;&lt;P&gt;But a new installation is out of the question for us, as you will lose all checkpoints&amp;nbsp;and a reread of all is the result.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 12:46:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675379#M18468</guid>
      <dc:creator>swaro_ck</dc:creator>
      <dc:date>2024-01-25T12:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 9.1.3: Universal Forwarder can't be updated</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675472#M18484</link>
      <description>&lt;P&gt;for us the upgrade worked when we added the parameter:&lt;BR /&gt;USE_LOCAL_SYSTEM=1&lt;BR /&gt;and the service was started as Local System&lt;BR /&gt;&lt;BR /&gt;when we did an uninstall of 9.1.2 and new install of 9.1.3 without the parameter the service was installed with the user&amp;nbsp;NT SERVICE\SplunkForwarder&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 07:54:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675472#M18484</guid>
      <dc:creator>kb_ama</dc:creator>
      <dc:date>2024-01-26T07:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 9.1.3: Universal Forwarder can't be updated</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675473#M18485</link>
      <description>&lt;P class="lia-align-justify"&gt;Great, thanks, that works.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 08:09:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/675473#M18485</guid>
      <dc:creator>swaro_ck</dc:creator>
      <dc:date>2024-01-26T08:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise 9.1.3: Universal Forwarder can't be updated</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/678666#M18756</link>
      <description>&lt;P&gt;Mine was failing also until I added the parameter above and install went through fine.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 13:20:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-9-1-3-Universal-Forwarder-can-t-be-updated/m-p/678666#M18756</guid>
      <dc:creator>ASierra</dc:creator>
      <dc:date>2024-02-26T13:20:15Z</dc:date>
    </item>
  </channel>
</rss>

