<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Install wizard ends prematurely in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421700#M10238</link>
    <description>&lt;P&gt;There is a default log file in &lt;CODE&gt;AppData/Local/Temp/splunk.log&lt;/CODE&gt;, and you can force more logging with &lt;CODE&gt;$ msiexec /I &amp;lt;splunk-MSI&amp;gt; /l*v &amp;lt;log-file&amp;gt;&lt;/CODE&gt;. The problem is almost always that Splunk cannot write to the disk because of a permission problem.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2019 21:34:21 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-08-01T21:34:21Z</dc:date>
    <item>
      <title>Splunk Install wizard ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421698#M10236</link>
      <description>&lt;P&gt;I upgraded from splunk 6.2.5 to 7.0. It seemed to work, but I get KV store errors. no luck on resolving those errors.&lt;/P&gt;

&lt;P&gt;I then tried to upgrade from 7.0 to 7.3 - and the wizard end prematurely. The O/S is a vm running W2K12.&lt;BR /&gt;
The splunk user is a domain user and an admin., the files/folder all have permissions for the user as full-control.&lt;/P&gt;

&lt;P&gt;Short of removing and re-installing - what can I be looking for?  The log file just says: "FatalError1"&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
eholz1&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 19:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421698#M10236</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2019-08-01T19:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Install wizard ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421699#M10237</link>
      <description>&lt;P&gt;forgot to mention the processor is intel - &lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 19:06:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421699#M10237</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2019-08-01T19:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Install wizard ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421700#M10238</link>
      <description>&lt;P&gt;There is a default log file in &lt;CODE&gt;AppData/Local/Temp/splunk.log&lt;/CODE&gt;, and you can force more logging with &lt;CODE&gt;$ msiexec /I &amp;lt;splunk-MSI&amp;gt; /l*v &amp;lt;log-file&amp;gt;&lt;/CODE&gt;. The problem is almost always that Splunk cannot write to the disk because of a permission problem.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 21:34:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421700#M10238</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-08-01T21:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Install wizard ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421701#M10239</link>
      <description>&lt;P&gt;Thanks, will check the file in the temp folder, I have been using the msiexec method to start it. I have new problem now!&lt;BR /&gt;
Ouch - the splunkd service will not stay running!&lt;/P&gt;

&lt;P&gt;Thanks for the input,&lt;/P&gt;

&lt;P&gt;eholz1&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 22:21:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421701#M10239</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2019-08-01T22:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Install wizard ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421702#M10240</link>
      <description>&lt;P&gt;So you got through the install wizard?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 22:37:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421702#M10240</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-08-01T22:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Install wizard ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421703#M10241</link>
      <description>&lt;P&gt;Hello woodcock,&lt;/P&gt;

&lt;P&gt;Well, it seems the issue is permissions as you indicated. A domain user is set to run the splunkd service.&lt;BR /&gt;
and from what I read the "splunkuser" should have access to D:\Program Files\Splunk....&lt;/P&gt;

&lt;P&gt;Does this user also have to have permissions on D:...?&lt;/P&gt;

&lt;P&gt;I am unable to set permissions on some files and folders under Splunk/... when I attempt to set the permissions some folders/files return "access denied"&lt;/P&gt;

&lt;P&gt;I will do more research tomorrow&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
eholz1&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 23:19:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421703#M10241</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2019-08-01T23:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Install wizard ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421704#M10242</link>
      <description>&lt;P&gt;Hi eholz1,&lt;/P&gt;

&lt;P&gt;The installer should be ensuring that all permissions are correct, so unless that is failing (which should be recorded in the &lt;CODE&gt;%TEMP%/splunk.log&lt;/CODE&gt; file that @woodcock mentioned---search for &lt;CODE&gt;icacls&lt;/CODE&gt;), there really shouldn't be a problem there.  However, what is true for some directories\files is that although the user that splunkd executes as has access, you as a member of Administrators, or whatever, may not.  That is somewhat unconventional for Windows, but it is not a bug per se.&lt;/P&gt;

&lt;P&gt;Hope this clarifies some.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Jo.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 02 Aug 2019 10:50:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421704#M10242</guid>
      <dc:creator>jhornsby_splunk</dc:creator>
      <dc:date>2019-08-02T10:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Install wizard ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421705#M10243</link>
      <description>&lt;P&gt;Hello jhornsby,&lt;/P&gt;

&lt;P&gt;Thanks for the reply, I will check icacls and see what it shows.&lt;BR /&gt;
there is no splunk.log file in %TEMP%, I will assume that %TEMP% is that user/appdata/local/splunk, etc.&lt;/P&gt;

&lt;P&gt;Thanks for the tip,  I will check things out (again) and get back one way or the other.&lt;/P&gt;

&lt;P&gt;eholz1&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 14:30:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421705#M10243</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2019-08-02T14:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Install wizard ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421706#M10244</link>
      <description>&lt;P&gt;Found the problem. there were two bogus ca pem files in the /etc/auth folder,&lt;BR /&gt;
I delete those, and the install completed.  Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 20:43:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Install-wizard-ends-prematurely/m-p/421706#M10244</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2019-08-02T20:43:20Z</dc:date>
    </item>
  </channel>
</rss>

