<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk enterprise in Installation</title>
    <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564266#M10561</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237579"&gt;@saddam979&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236694"&gt;@SanjayReddy&lt;/a&gt;&amp;nbsp;said, probably the problem is that yopu didn't run the setup as an administrator.&lt;/P&gt;&lt;P&gt;Anyway, in $SPLUNK_HOME\var\log\splunk you should find the "first_install.log" file containing all the logs of your failed installation and the other Splunk logs to understand what happened.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 23 Aug 2021 07:24:44 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-08-23T07:24:44Z</dc:date>
    <item>
      <title>splunk enterprise</title>
      <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/563851#M10542</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I am trying to install Splunk enterprise in my windows 10.&lt;/P&gt;&lt;P&gt;But i&amp;nbsp; am getting this error as splunk enterprise setup wizard ended prematurely.&lt;/P&gt;&lt;P&gt;I have tried multiple time still get the same error .&lt;/P&gt;&lt;P&gt;Please any once can help me in this .&lt;/P&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk  error.PNG" style="width: 624px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15622i0CD130109022D66C/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk  error.PNG" alt="splunk  error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 19:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/563851#M10542</guid>
      <dc:creator>saddam979</dc:creator>
      <dc:date>2021-08-18T19:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/563855#M10543</link>
      <description>&lt;P&gt;In event viewer, under applications, please check for event ids 1001 to 1017. It should give you an idea as to why the installation failed.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 20:09:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/563855#M10543</guid>
      <dc:creator>shivanshu1593</dc:creator>
      <dc:date>2021-08-18T20:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564257#M10559</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237579"&gt;@saddam979&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Have you tried running setup file with run as administartaor&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;try from CMD as administrator&lt;BR /&gt;&lt;BR /&gt;msiexec.exe /i splunk-&amp;lt;...&amp;gt;-x64-release.msi&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Installation/InstallonWindowsviathecommandline#Install_Splunk_Enterprise_from_the_command_line" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Installation/InstallonWindowsviathecommandline#Install_Splunk_Enterprise_from_the_command_line&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 04:55:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564257#M10559</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2021-08-23T04:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564266#M10561</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237579"&gt;@saddam979&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236694"&gt;@SanjayReddy&lt;/a&gt;&amp;nbsp;said, probably the problem is that yopu didn't run the setup as an administrator.&lt;/P&gt;&lt;P&gt;Anyway, in $SPLUNK_HOME\var\log\splunk you should find the "first_install.log" file containing all the logs of your failed installation and the other Splunk logs to understand what happened.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 07:24:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564266#M10561</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-08-23T07:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564584#M10569</link>
      <description>&lt;P&gt;&amp;nbsp;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236694"&gt;@SanjayReddy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;As per your&amp;nbsp; &amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&amp;nbsp;suggestion.&lt;/P&gt;&lt;P&gt;I have tried to run the setup n CMD as admin with this command .&lt;/P&gt;&lt;P&gt;msiexec.exe /i splunk-&amp;lt;splunk-8.2.2-87344edfcdb4&amp;gt;-x64-release.msi&lt;/P&gt;&lt;P&gt;But i get the error message as "The system cannot find the file specified."&lt;/P&gt;&lt;P&gt;Even i have tried msiexec/i splunkfilename.msi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get the error as " This installation&amp;nbsp; could not be opened.&lt;/P&gt;&lt;P&gt;I have attached the pic for the reference.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;The path which you have mentioned to collect the log and investigate is not available in my system. May be because it is not getting installed in the system.&lt;/P&gt;&lt;P&gt;Please help with your suggestion.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="msiexec/i splunkfilename.msi" style="width: 465px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15708i4279BD2F788F3608/image-size/large?v=v2&amp;amp;px=999" role="button" title="result_when run other command.PNG" alt="msiexec/i splunkfilename.msi" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;msiexec/i splunkfilename.msi&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="msiexec.exe /i splunk-&amp;lt;splunk-8.2.2-87344edfcdb4&amp;gt;-x64-release.msi" style="width: 849px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15709iCA5A384C1EFCEA23/image-size/large?v=v2&amp;amp;px=999" role="button" title="result_whenrun.PNG" alt="msiexec.exe /i splunk-&amp;lt;splunk-8.2.2-87344edfcdb4&amp;gt;-x64-release.msi" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;msiexec.exe /i splunk-&amp;lt;splunk-8.2.2-87344edfcdb4&amp;gt;-x64-release.msi&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 16:42:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564584#M10569</guid>
      <dc:creator>saddam979</dc:creator>
      <dc:date>2021-08-24T16:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564585#M10570</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/61125"&gt;@shivanshu1593&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for the suggestion i have checked the logs.&lt;/P&gt;&lt;P&gt;But not able to get the exact event ID..&lt;/P&gt;&lt;P&gt;I installed the Software today and checked for the failed event.&lt;/P&gt;&lt;P&gt;I got this :-Event ID 1552.&lt;BR /&gt;User Profile Service&lt;/P&gt;&lt;P&gt;With the description as :-&amp;nbsp;User hive is loaded by another process (Registry Lock) Process name: C:\Windows\System32\SecurityHealthService.exe, PID: 13308, ProfSvc PID: 2024&lt;/P&gt;&lt;P&gt;Can you help me with this further in this case.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 16:52:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564585#M10570</guid>
      <dc:creator>saddam979</dc:creator>
      <dc:date>2021-08-24T16:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564624#M10574</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237579"&gt;@saddam979&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for your reply.&lt;BR /&gt;&lt;BR /&gt;you need to mention location of the splunk msi file while running the command&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;exmaple&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;msiexec.exe /i C:\Users\Desktop\splunk-8.2.2-87344edfcdb4-x64-release.msi&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps to install the splunk on systme&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 04:03:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564624#M10574</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2021-08-25T04:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564644#M10575</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;as it already said you must add full path for psi package on cmd line. I'm using this when installing e.g. UF on windows.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;msiexec.exe /i &amp;lt;path to temp&amp;gt;/splunkforwarder-&amp;lt;XXXXX&amp;gt;-x64-release.msi AGREETOLICENSE=yes LAUNCHSPLUNK=no SERVICESTARTTYPE=auto /quiet /l*v install-log.txt&lt;/LI-CODE&gt;&lt;P&gt;After that and before first start I will add TA for connecting DS and information about splunk indexers or next hops if those are e.g. IHF. All those steps must do on user which have Admin role/rights. And As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;said you could find splunk logs under %SPLUNK_HOME% and installation logs is in this install-log.txt file.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 06:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564644#M10575</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-08-25T06:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564791#M10584</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236694"&gt;@SanjayReddy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for the suggestion.&lt;/P&gt;&lt;P&gt;As per your request i have run the CMD as an administrator.&lt;/P&gt;&lt;P&gt;File is located on my desktop.&lt;/P&gt;&lt;P&gt;when I run the command as :&amp;nbsp;msiexec.exe /i C:\Users\Desktop\splunk-8.2.2-87344edfcdb4-x64-release.msi&amp;nbsp;&lt;/P&gt;&lt;P&gt;It gives the error as&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="installation_pack error.PNG" style="width: 313px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15744iDA2E647C1BCF558A/image-dimensions/313x189?v=v2" width="313" height="189" role="button" title="installation_pack error.PNG" alt="installation_pack error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I get this error.&lt;/P&gt;&lt;P&gt;Then i checked the services for the windows installer&amp;nbsp; i have started that and then used this cmd command it get this.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="when run the command.PNG" style="width: 523px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15745i96AF29CE8A0F76AA/image-size/large?v=v2&amp;amp;px=999" role="button" title="when run the command.PNG" alt="when run the command.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After pressing Okay nothing happen.&lt;/P&gt;&lt;P&gt;Not sure what is wrong.&lt;/P&gt;&lt;P&gt;Please help me in this .&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 20:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564791#M10584</guid>
      <dc:creator>saddam979</dc:creator>
      <dc:date>2021-08-25T20:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564826#M10587</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;As it was said, you must use the full path here. You are probably missing user id on previous path? And if you look my previous post and add that debugging part to the end of command you will get more information what went wrong or what it has done.&lt;/P&gt;&lt;PRE&gt;/l*v install-log.txt&lt;/PRE&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 06:09:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-enterprise/m-p/564826#M10587</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-08-26T06:09:26Z</dc:date>
    </item>
  </channel>
</rss>

