<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunkd windows service marked for deletion after upgrade in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-windows-service-marked-for-deletion-after-upgrade/m-p/47172#M8952</link>
    <description>&lt;P&gt;The services recreated properly after rebooted &amp;amp; ran the "splunk enable boot-start"  command.&lt;BR /&gt;
Now I have some other issues&lt;/P&gt;</description>
    <pubDate>Tue, 22 Feb 2011 04:55:20 GMT</pubDate>
    <dc:creator>yazapage</dc:creator>
    <dc:date>2011-02-22T04:55:20Z</dc:date>
    <item>
      <title>splunkd windows service marked for deletion after upgrade</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-windows-service-marked-for-deletion-after-upgrade/m-p/47169#M8949</link>
      <description>&lt;P&gt;I upgraded from Splunk 3.4.9 to 4.0.1 and then to 4.1.5 using localsystem as the account.&lt;/P&gt;

&lt;P&gt;After I upgraded the second time the splunkd service was disabled.&lt;/P&gt;

&lt;P&gt;I tried to reactivate after changing to a domain account (with the appropriate permissions).
The service is "marked for deletion" and will not allow me to change user accounts or start.&lt;/P&gt;

&lt;P&gt;Where do I go from here?  Do I need to start my upgrades all over again?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Feb 2011 03:01:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-windows-service-marked-for-deletion-after-upgrade/m-p/47169#M8949</guid>
      <dc:creator>yazapage</dc:creator>
      <dc:date>2011-02-19T03:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd windows service marked for deletion after upgrade</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-windows-service-marked-for-deletion-after-upgrade/m-p/47170#M8950</link>
      <description>&lt;P&gt;Yazapage,&lt;/P&gt;

&lt;P&gt;it seems like the "splunkd" windows services is stuck in an un-deterministic state.  Fist of all once Splunk is running as a Local System user, all of the files created at run time will be owned by that user.  Switching to a Domain user account it will not do any good.  I suggest you switch both services, including splunkweb back to Local System User again.&lt;/P&gt;

&lt;P&gt;As far as the splunkd service, you may need to reboot the machine for Windows Service manager to release that service.  Once the machines comes backup online again, the services manager will have deleted the service, and you'll need to create another one.&lt;/P&gt;

&lt;P&gt;As far as splunkweb, just open service manager and tell splunkweb service to run as Local System user.&lt;/P&gt;

&lt;P&gt;Since splunkd service is delete now, to created again open a terminal and go to Splunk home bin directory, eg: &lt;/P&gt;

&lt;P&gt;cd c:\Program Files\Splunk\bin&lt;/P&gt;

&lt;P&gt;From there run:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;splunk enable boot-start&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;This command will try and create both services, splunkd and splunkweb allover again.&lt;/P&gt;

&lt;P&gt;Start splunk:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;splunk start&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Let us know how it goes.&lt;/P&gt;

&lt;P&gt;Thanks,
Ledio&lt;/P&gt;</description>
      <pubDate>Sat, 19 Feb 2011 03:45:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-windows-service-marked-for-deletion-after-upgrade/m-p/47170#M8950</guid>
      <dc:creator>Ledio_Ago</dc:creator>
      <dc:date>2011-02-19T03:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd windows service marked for deletion after upgrade</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-windows-service-marked-for-deletion-after-upgrade/m-p/47171#M8951</link>
      <description>&lt;P&gt;Services marked for deletion won't be accessible until the server is restarted.  After you bounce the box you should be able to create the service again.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Feb 2011 09:00:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-windows-service-marked-for-deletion-after-upgrade/m-p/47171#M8951</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2011-02-19T09:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd windows service marked for deletion after upgrade</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-windows-service-marked-for-deletion-after-upgrade/m-p/47172#M8952</link>
      <description>&lt;P&gt;The services recreated properly after rebooted &amp;amp; ran the "splunk enable boot-start"  command.&lt;BR /&gt;
Now I have some other issues&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2011 04:55:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-windows-service-marked-for-deletion-after-upgrade/m-p/47172#M8952</guid>
      <dc:creator>yazapage</dc:creator>
      <dc:date>2011-02-22T04:55:20Z</dc:date>
    </item>
  </channel>
</rss>

