<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why am I unable to install Splunk universal forwarder on Windows server 2012 R2? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302068#M57060</link>
    <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;Unable to install Splunk universal forwarder on Windows server 2012 R2, please help to solve this issue.&lt;/P&gt;

&lt;P&gt;Logs&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-04-2017 21:49:01.089 +0530 INFO  ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
04-04-2017 21:49:01.089 +0530 INFO  ServerConfig - Host name option is "".
04-04-2017 21:49:03.538 +0530 INFO  loader - Running utility: "check-transforms-keys"
04-04-2017 21:49:03.538 +0530 INFO  loader - Getting configuration data from: C:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml
04-04-2017 21:49:03.538 +0530 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:03.538 +0530 INFO  loader - loading modules from C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:03.553 +0530 INFO  loader - Writing out composite configuration file: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml
04-04-2017 21:49:05.363 +0530 INFO  loader - Splunkd starting (build 67571ef4b87d).
04-04-2017 21:49:05.363 +0530 INFO  loader - System info: Windows, TSMSRV2, 2, 6, x64.
04-04-2017 21:49:05.363 +0530 INFO  loader - Detected 1 (virtual) CPUs, 1 CPU cores, and 16383MB RAM
04-04-2017 21:49:05.363 +0530 INFO  loader - Maximum number of threads (approximate): 8191
04-04-2017 21:49:05.363 +0530 INFO  loader - Arguments are: "rest" "--noauth" "POST" "/services/apps/local/SplunkUniversalForwarder/enable"
04-04-2017 21:49:05.363 +0530 INFO  loader - Getting configuration data from: C:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml
04-04-2017 21:49:05.363 +0530 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:05.363 +0530 INFO  loader - loading modules from C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:05.363 +0530 INFO  loader - Writing out composite configuration file: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml
04-04-2017 21:49:05.379 +0530 INFO  ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
04-04-2017 21:49:05.379 +0530 INFO  ServerConfig - Host name option is "".
04-04-2017 21:49:05.394 +0530 WARN  AuthenticationManagerSplunk - Seed file is not present. Defaulting to generic username/pass pair.
04-04-2017 21:49:05.410 +0530 WARN  UserManagerPro - Can't find [distributedSearch] stanza in distsearch.conf, using default authtoken HTTP timeouts
04-04-2017 21:49:06.720 +0530 ERROR LimitsHandler - Configuration from app=SplunkUniversalForwarder does not support reload: limits.conf/[thruput]/maxKBps
04-04-2017 21:49:06.720 +0530 ERROR ApplicationUpdater - Error reloading SplunkUniversalForwarder: handler for limits (access_endpoints /server/status/limits/general): Bad Request
04-04-2017 21:49:06.720 +0530 ERROR ApplicationUpdater - Error reloading SplunkUniversalForwarder: handler for server (http_post /replication/configuration/whitelist-reload): Application does not exist: Not Found
04-04-2017 21:49:06.720 +0530 ERROR ApplicationUpdater - Error reloading SplunkUniversalForwarder: handler for web (http_post /server/control/restart_webui_polite): Application does not exist: Not Found
04-04-2017 21:49:06.720 +0530 WARN  LocalAppsAdminHandler - User 'splunk-system-user' triggered the 'enable' action on app 'SplunkUniversalForwarder', and the following objects required a restart: default-mode, limits, server, web
04-04-2017 21:49:07.095 +0530 INFO  loader - Splunkd starting (build 67571ef4b87d).
04-04-2017 21:49:07.095 +0530 INFO  loader - System info: Windows, TSMSRV2, 2, 6, x64.
04-04-2017 21:49:07.095 +0530 INFO  loader - Detected 1 (virtual) CPUs, 1 CPU cores, and 16383MB RAM
04-04-2017 21:49:07.095 +0530 INFO  loader - Maximum number of threads (approximate): 8191
04-04-2017 21:49:07.095 +0530 INFO  loader - Arguments are: "rest" "--noauth" "POST" "/servicesNS/nobody/SplunkUniversalForwarder/data/outputs/tcp/server" "name=192.168.6.74:9997"
04-04-2017 21:49:07.095 +0530 INFO  loader - Getting configuration data from: C:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml
04-04-2017 21:49:07.095 +0530 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:07.095 +0530 INFO  loader - loading modules from C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:07.095 +0530 INFO  loader - Writing out composite configuration file: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml
04-04-2017 21:49:07.126 +0530 INFO  ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
04-04-2017 21:49:07.126 +0530 INFO  ServerConfig - Host name option is "".
04-04-2017 21:49:07.142 +0530 WARN  UserManagerPro - Can't find [distributedSearch] stanza in distsearch.conf, using default authtoken HTTP timeouts
04-04-2017 21:49:07.563 +0530 INFO  loader - Splunkd starting (build 67571ef4b87d).
04-04-2017 21:49:07.563 +0530 INFO  loader - System info: Windows, TSMSRV2, 2, 6, x64.
04-04-2017 21:49:07.563 +0530 INFO  loader - Detected 1 (virtual) CPUs, 1 CPU cores, and 16383MB RAM
04-04-2017 21:49:07.563 +0530 INFO  loader - Maximum number of threads (approximate): 8191
04-04-2017 21:49:07.563 +0530 INFO  loader - Arguments are: "rest" "--noauth" "POST" "/servicesNS/nobody/SplunkUniversalForwarder/admin/deploymentclient/deployment-client" "targetUri=192.168.6.74:8089"
04-04-2017 21:49:07.563 +0530 INFO  loader - Getting configuration data from: C:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml
04-04-2017 21:49:07.563 +0530 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:07.563 +0530 INFO  loader - loading modules from C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:07.563 +0530 INFO  loader - Writing out composite configuration file: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml
04-04-2017 21:49:07.563 +0530 INFO  ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
04-04-2017 21:49:07.563 +0530 INFO  ServerConfig - Host name option is "".
04-04-2017 21:49:07.594 +0530 WARN  UserManagerPro - Can't find [distributedSearch] stanza in distsearch.conf, using default authtoken HTTP timeouts
04-04-2017 21:49:07.610 +0530 WARN  DC:PhonehomeThread - Phonehome thread is now shutdown.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 04 Apr 2017 16:26:45 GMT</pubDate>
    <dc:creator>sivaksk147</dc:creator>
    <dc:date>2017-04-04T16:26:45Z</dc:date>
    <item>
      <title>Why am I unable to install Splunk universal forwarder on Windows server 2012 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302068#M57060</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;Unable to install Splunk universal forwarder on Windows server 2012 R2, please help to solve this issue.&lt;/P&gt;

&lt;P&gt;Logs&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-04-2017 21:49:01.089 +0530 INFO  ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
04-04-2017 21:49:01.089 +0530 INFO  ServerConfig - Host name option is "".
04-04-2017 21:49:03.538 +0530 INFO  loader - Running utility: "check-transforms-keys"
04-04-2017 21:49:03.538 +0530 INFO  loader - Getting configuration data from: C:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml
04-04-2017 21:49:03.538 +0530 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:03.538 +0530 INFO  loader - loading modules from C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:03.553 +0530 INFO  loader - Writing out composite configuration file: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml
04-04-2017 21:49:05.363 +0530 INFO  loader - Splunkd starting (build 67571ef4b87d).
04-04-2017 21:49:05.363 +0530 INFO  loader - System info: Windows, TSMSRV2, 2, 6, x64.
04-04-2017 21:49:05.363 +0530 INFO  loader - Detected 1 (virtual) CPUs, 1 CPU cores, and 16383MB RAM
04-04-2017 21:49:05.363 +0530 INFO  loader - Maximum number of threads (approximate): 8191
04-04-2017 21:49:05.363 +0530 INFO  loader - Arguments are: "rest" "--noauth" "POST" "/services/apps/local/SplunkUniversalForwarder/enable"
04-04-2017 21:49:05.363 +0530 INFO  loader - Getting configuration data from: C:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml
04-04-2017 21:49:05.363 +0530 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:05.363 +0530 INFO  loader - loading modules from C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:05.363 +0530 INFO  loader - Writing out composite configuration file: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml
04-04-2017 21:49:05.379 +0530 INFO  ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
04-04-2017 21:49:05.379 +0530 INFO  ServerConfig - Host name option is "".
04-04-2017 21:49:05.394 +0530 WARN  AuthenticationManagerSplunk - Seed file is not present. Defaulting to generic username/pass pair.
04-04-2017 21:49:05.410 +0530 WARN  UserManagerPro - Can't find [distributedSearch] stanza in distsearch.conf, using default authtoken HTTP timeouts
04-04-2017 21:49:06.720 +0530 ERROR LimitsHandler - Configuration from app=SplunkUniversalForwarder does not support reload: limits.conf/[thruput]/maxKBps
04-04-2017 21:49:06.720 +0530 ERROR ApplicationUpdater - Error reloading SplunkUniversalForwarder: handler for limits (access_endpoints /server/status/limits/general): Bad Request
04-04-2017 21:49:06.720 +0530 ERROR ApplicationUpdater - Error reloading SplunkUniversalForwarder: handler for server (http_post /replication/configuration/whitelist-reload): Application does not exist: Not Found
04-04-2017 21:49:06.720 +0530 ERROR ApplicationUpdater - Error reloading SplunkUniversalForwarder: handler for web (http_post /server/control/restart_webui_polite): Application does not exist: Not Found
04-04-2017 21:49:06.720 +0530 WARN  LocalAppsAdminHandler - User 'splunk-system-user' triggered the 'enable' action on app 'SplunkUniversalForwarder', and the following objects required a restart: default-mode, limits, server, web
04-04-2017 21:49:07.095 +0530 INFO  loader - Splunkd starting (build 67571ef4b87d).
04-04-2017 21:49:07.095 +0530 INFO  loader - System info: Windows, TSMSRV2, 2, 6, x64.
04-04-2017 21:49:07.095 +0530 INFO  loader - Detected 1 (virtual) CPUs, 1 CPU cores, and 16383MB RAM
04-04-2017 21:49:07.095 +0530 INFO  loader - Maximum number of threads (approximate): 8191
04-04-2017 21:49:07.095 +0530 INFO  loader - Arguments are: "rest" "--noauth" "POST" "/servicesNS/nobody/SplunkUniversalForwarder/data/outputs/tcp/server" "name=192.168.6.74:9997"
04-04-2017 21:49:07.095 +0530 INFO  loader - Getting configuration data from: C:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml
04-04-2017 21:49:07.095 +0530 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:07.095 +0530 INFO  loader - loading modules from C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:07.095 +0530 INFO  loader - Writing out composite configuration file: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml
04-04-2017 21:49:07.126 +0530 INFO  ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
04-04-2017 21:49:07.126 +0530 INFO  ServerConfig - Host name option is "".
04-04-2017 21:49:07.142 +0530 WARN  UserManagerPro - Can't find [distributedSearch] stanza in distsearch.conf, using default authtoken HTTP timeouts
04-04-2017 21:49:07.563 +0530 INFO  loader - Splunkd starting (build 67571ef4b87d).
04-04-2017 21:49:07.563 +0530 INFO  loader - System info: Windows, TSMSRV2, 2, 6, x64.
04-04-2017 21:49:07.563 +0530 INFO  loader - Detected 1 (virtual) CPUs, 1 CPU cores, and 16383MB RAM
04-04-2017 21:49:07.563 +0530 INFO  loader - Maximum number of threads (approximate): 8191
04-04-2017 21:49:07.563 +0530 INFO  loader - Arguments are: "rest" "--noauth" "POST" "/servicesNS/nobody/SplunkUniversalForwarder/admin/deploymentclient/deployment-client" "targetUri=192.168.6.74:8089"
04-04-2017 21:49:07.563 +0530 INFO  loader - Getting configuration data from: C:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml
04-04-2017 21:49:07.563 +0530 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:07.563 +0530 INFO  loader - loading modules from C:\Program Files\SplunkUniversalForwarder\etc\modules
04-04-2017 21:49:07.563 +0530 INFO  loader - Writing out composite configuration file: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml
04-04-2017 21:49:07.563 +0530 INFO  ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
04-04-2017 21:49:07.563 +0530 INFO  ServerConfig - Host name option is "".
04-04-2017 21:49:07.594 +0530 WARN  UserManagerPro - Can't find [distributedSearch] stanza in distsearch.conf, using default authtoken HTTP timeouts
04-04-2017 21:49:07.610 +0530 WARN  DC:PhonehomeThread - Phonehome thread is now shutdown.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 04 Apr 2017 16:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302068#M57060</guid>
      <dc:creator>sivaksk147</dc:creator>
      <dc:date>2017-04-04T16:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to install Splunk universal forwarder on Windows server 2012 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302069#M57061</link>
      <description>&lt;P&gt;Here is some documentation that might be helpful from the Forwarder Manual:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Install a Windows universal forwarder from an installer:
&lt;A href="http://docs.splunk.com/Documentation/Forwarder/6.5.3/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller"&gt;http://docs.splunk.com/Documentation/Forwarder/6.5.3/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller&lt;/A&gt;
(Be sure to configure the Deployment Server and the Receiving Indexer in steps 8 &amp;amp; 9.) &lt;/LI&gt;
&lt;LI&gt;Install a Windows universal forwarder from the command line:
&lt;A href="http://docs.splunk.com/Documentation/Forwarder/6.5.3/Forwarder/InstallaWindowsuniversalforwarderfromthecommandline"&gt;http://docs.splunk.com/Documentation/Forwarder/6.5.3/Forwarder/InstallaWindowsuniversalforwarderfromthecommandline&lt;/A&gt;
(Be sure to specify a Deployment Server and the Receiving Indexer.)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Here are some simple step-by-step instructions from a universal forwarder configuration in Splunk Light that might give you an idea of a basic configuration:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/SplunkLight/6.5.1612/GettingStarted/GettingdataintoSplunkLightusingWindows"&gt;http://docs.splunk.com/Documentation/SplunkLight/6.5.1612/GettingStarted/GettingdataintoSplunkLightusingWindows&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2017 18:23:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302069#M57061</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2017-04-04T18:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to install Splunk universal forwarder on Windows server 2012 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302070#M57062</link>
      <description>&lt;P&gt;Thank you for the response, I have tried installing 6.1.3 UF it's perfectly working fine on windows server 2012 R2 . the latest version of is not working on any of the windows server 2012 R2 not too sure why?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 06:21:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302070#M57062</guid>
      <dc:creator>sivaksk147</dc:creator>
      <dc:date>2017-04-05T06:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to install Splunk universal forwarder on Windows server 2012 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302071#M57063</link>
      <description>&lt;P&gt;Which version did you try to install on 4-April?&lt;/P&gt;

&lt;P&gt;Can you try 6.4.6? There was a fix implemented for an issue found when deploying servers via an SCCM-like solution.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 13:02:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302071#M57063</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2017-04-05T13:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to install Splunk universal forwarder on Windows server 2012 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302072#M57064</link>
      <description>&lt;P&gt;I'm having this exact issue on 2008 R2 as well as 2012 R2 with both 6.5.2 and 6.5.3 (see below) and it's holding up a good chunk of installations. Have you had any luck?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;4-28-2017 10:14:38.923 -0400 WARN  DC:PhonehomeThread - Phonehome thread is now shutdown.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 28 Apr 2017 14:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-install-Splunk-universal-forwarder-on-Windows/m-p/302072#M57064</guid>
      <dc:creator>asofo</dc:creator>
      <dc:date>2017-04-28T14:20:29Z</dc:date>
    </item>
  </channel>
</rss>

