<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error &amp;quot;Wizard Ended Prematurely&amp;quot;? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216300#M42588</link>
    <description>&lt;P&gt;krellinst ,&lt;BR /&gt;
I had to do the exact process that employed back last year when I went from 5.0.3 to 6.1.3. The worst was having to do it for the 300 v5.0.3 forwarders we had installed.  Seems upgrading from 5.x to 6.0 was good for most but if you went from 5.x to 6.1.0 or higher this issue would present itself.  I wish I had come across this question earlier for I could of saved you a couple of weeks of headaches by given you the exact process you ended up employing.&lt;/P&gt;</description>
    <pubDate>Wed, 04 May 2016 14:15:33 GMT</pubDate>
    <dc:creator>afret2007</dc:creator>
    <dc:date>2016-05-04T14:15:33Z</dc:date>
    <item>
      <title>Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216289#M42577</link>
      <description>&lt;P&gt;I am trying to upgrade the collectors on a few Windows Servers because I had a security come back saying my version had some issues.  The readme in program files says I have Splunk 5.0.3.&lt;/P&gt;

&lt;P&gt;I am trying to install 6.4 64-bit.&lt;/P&gt;

&lt;P&gt;I am receiving a general error saying the setup ended prematurely and everything was rolled back.  This is happening on every server I have attempted to far.  &lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 21:18:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216289#M42577</guid>
      <dc:creator>krellinst</dc:creator>
      <dc:date>2016-04-18T21:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216290#M42578</link>
      <description>&lt;P&gt;What user are you running the installation as?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 22:33:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216290#M42578</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-04-18T22:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216291#M42579</link>
      <description>&lt;P&gt;As Chris is getting to, the user must have the ability to write to the program files folder and do other things too.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 22:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216291#M42579</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-04-18T22:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216292#M42580</link>
      <description>&lt;P&gt;I am running it as myself who has admin privileges.  I have also tried running it as the domain admin.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 14:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216292#M42580</guid>
      <dc:creator>krellinst</dc:creator>
      <dc:date>2016-04-19T14:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216293#M42581</link>
      <description>&lt;P&gt;Please check your windows event logs for the error and give us the error details you're getting.  start-&amp;gt;run-&amp;gt;eventvwr.msc [ok/enter]&lt;/P&gt;

&lt;P&gt;I believe it will fall under system or application logs.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 15:59:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216293#M42581</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-04-19T15:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216294#M42582</link>
      <description>&lt;P&gt;I am seeing no error just informationals.  The last one being - Ending a Windows Installer transaction: C:\Users\rpearson\Desktop\splunkforwarder-6.4.0-f2c836328108-x64-release.msi. Client Process Id: 3096.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 19:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216294#M42582</guid>
      <dc:creator>krellinst</dc:creator>
      <dc:date>2016-04-19T19:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216295#M42583</link>
      <description>&lt;P&gt;Upgrading from 5.0.X to 6.4.X is not officially supported, I believe you will need to upgrade in a step-process.  See the following link for more info, scroll down on the page to the "Upgrade from..." sections:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/HowtoupgradeSplunk"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/HowtoupgradeSplunk&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 19:55:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216295#M42583</guid>
      <dc:creator>jbailey_splunk</dc:creator>
      <dc:date>2016-04-20T19:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216296#M42584</link>
      <description>&lt;P&gt;Also, run the install in administrative mode.  &lt;/P&gt;

&lt;P&gt;Depending on the exact flavor of Windows, you might have to right-click it and "Run as administrator".  If that doesn't work, click start, type cmd but instead of pressing enter or clicking it, RIGHT click it and select Run as administrator.  From there launch your installer (e.g. if it's in the root of c:\, then type &lt;CODE&gt;msiexec /i c:\splunkuniversalforwader-6.4.blah.msi&lt;/CODE&gt; though of course you can type &lt;CODE&gt;msiexec /i c:\splun&amp;lt;tab key&amp;gt;&lt;/CODE&gt; to make life easier.)&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 14:46:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216296#M42584</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-04-22T14:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216297#M42585</link>
      <description>&lt;P&gt;This also is not not working.  What I had to do was remove every Registry entry with splunk in it and remove the splunk directory.  Reboot and then the install happens just fine.  This worked on all 6 servers I was trying it on.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 19:03:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216297#M42585</guid>
      <dc:creator>krellinst</dc:creator>
      <dc:date>2016-04-22T19:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216298#M42586</link>
      <description>&lt;P&gt;RE:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;krellinst  rich7177 ♦ · Apr 22 at 12:03 PM  
This also is not not working. What I had to do was remove every Registry entry with splunk in it and remove the splunk directory. Reboot and then the install happens just fine. This worked on all 6 servers I was trying it on.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hunh.... I repeated the install without doing the removal and the second time it said it completed successfully.  But now I am having other problems.&lt;/P&gt;

&lt;P&gt;I will try your suggestion.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 13:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216298#M42586</guid>
      <dc:creator>reswob4</dc:creator>
      <dc:date>2016-05-04T13:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216299#M42587</link>
      <description>&lt;P&gt;AH!  Do you have SCCM in your environment?  There is a bug in the installer for the UF in all 6.3.x versions which gobs up your registry when you attempt a silent install via SCCM (and it &lt;EM&gt;could&lt;/EM&gt; affect other scenarios as well - if yours had nothing ever to do with SCCM or silent installs, please let us know!).&lt;/P&gt;

&lt;P&gt;What I found as a resolution that's at least &lt;EM&gt;slightly&lt;/EM&gt; less annoying is to (and this is MUCH abbreviated, if it doesn't work for you drop a line here and I can give more detail on some parts):&lt;/P&gt;

&lt;P&gt;*&lt;EM&gt;TEST THIS CAREFULLY, treat it as "free internet help for my complex problem" e.g. be very careful.  And no warranties! *&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Open up the registry key &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[HKEY_CLASSES_ROOT\Installer\UpgradeCodes\13631B46466632F4FA2E89CF8E9602DB]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Record the keys it has listed under it.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"FC94181CE1B8D094287835AC8D72EBB6"=""
"E59ED7ED18A676D4D942E4E5BE369938"=""
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Those were the ones in my case, yours may differ.  Those three values you'll want to find as keys and delete out of &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[HKEY_CLASSES_ROOT\Installer\Products
[HKEY_CLASSES_ROOT\Installer\Features
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The "Products" section can obviously be tied back to the Splunk Universal Forwarder (says so in the "ProductName" value).  The "Features" section is a little less obvious. What I've been seeing is two of the three keys exist with stubs or nothing identifiable (or even interesting). &lt;/P&gt;

&lt;P&gt;Once you have identified those on a few systems, as long as they're pretty predictable, you could create a batch file like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;@echo off
dir "C:\Program files\splunk*"
IF %ERRORLEVEL%==0 GOTO EXISTS

REG DELETE HKCR\Installer\Features\E59ED7ED18A676D4D942E4E5BE369938 /f
REG DELETE HKCR\Installer\Features\FC94181CE1B8D094287835AC8D72EBB6 /f
REG DELETE HKCR\Installer\Products\E59ED7ED18A676D4D942E4E5BE369938 /f
REG DELETE HKCR\Installer\Products\FC94181CE1B8D094287835AC8D72EBB6 /f
REG DELETE HKCR\Installer\UpgradeCodes\13631B46466632F4FA2E89CF8E9602DB /f

GOTO END
:EXISTS
ECHO No changes made: UF exists

:END
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you save that as "regclear.cmd", you could then run it (TEST THIS A LOT!) on a remote system with one of the sysinternals utilities "psexec", like &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;psexec \\myComputerName -c -s -h regclear.cmd
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When you are happy it doesn't borken up other things, you can generate a list of the remaining servers and save them in a file and do them all at once by using an alternative syntax&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;psexec @systems.txt -c -s -h regclear.cmd
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or, for simpler environments, just save the regclear.cmd somewhere accessible from all the systems, log into them and run it once.&lt;/P&gt;

&lt;P&gt;HOpefully this will save you time and effort.&lt;/P&gt;

&lt;P&gt;And reply back about SCCM!  We thought (well, I thought, I'm not positive what Splunk knows in addition to that) it was an SCCM silent install issue only, but it's possible it could affect other types of installs.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 13:26:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216299#M42587</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-05-04T13:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to upgrade Windows universal forwarders from Splunk 5.0.3 to 6.4, why am I getting error "Wizard Ended Prematurely"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216300#M42588</link>
      <description>&lt;P&gt;krellinst ,&lt;BR /&gt;
I had to do the exact process that employed back last year when I went from 5.0.3 to 6.1.3. The worst was having to do it for the 300 v5.0.3 forwarders we had installed.  Seems upgrading from 5.x to 6.0 was good for most but if you went from 5.x to 6.1.0 or higher this issue would present itself.  I wish I had come across this question earlier for I could of saved you a couple of weeks of headaches by given you the exact process you ended up employing.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 14:15:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-upgrade-Windows-universal-forwarders-from-Splunk-5-0-3/m-p/216300#M42588</guid>
      <dc:creator>afret2007</dc:creator>
      <dc:date>2016-05-04T14:15:33Z</dc:date>
    </item>
  </channel>
</rss>

