<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I fix this error: Universal Forwarder 9 Setup Ended Prematurely on Server 2019? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612567#M11894</link>
    <description>&lt;P&gt;Thanks for the follow up.&amp;nbsp; I have checked and there are no indications of lingering installations.&amp;nbsp; However, I imagine there must be something in the registry that is flagging the installer but I will not haphazardly remove any "splunk" mentions from my Domain Controller registry until Splunk indicates exactly which HKEY paths to check and are safe to delete.&amp;nbsp; Do you have any suggestions of registry keys and or folders that need to be removed before proceeding with a new attempt to install?&amp;nbsp; Should I just open a support ticket and have official support address this issue?&lt;/P&gt;</description>
    <pubDate>Fri, 09 Sep 2022 12:31:32 GMT</pubDate>
    <dc:creator>jvcog</dc:creator>
    <dc:date>2022-09-09T12:31:32Z</dc:date>
    <item>
      <title>How do I fix this error: Universal Forwarder 9 Setup Ended Prematurely on Server 2019?</title>
      <link>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612450#M11887</link>
      <description>&lt;P&gt;I've installed the forwarded on several other domain controllers in our environment but these last 2 keep failing, throwing the all too enigmatic "setup ended prematurely" error.&amp;nbsp; "Like a F-18 bro!"&lt;/P&gt;
&lt;P&gt;They are Windows Server 2019&lt;BR /&gt;9.0 forwarder 64-bit installer&lt;BR /&gt;Regardless that the log states "SplunkForwarder already exists"; there is no current installation of the forwarder (but I have attempted it several times)&lt;/P&gt;
&lt;P&gt;The logs don't seem to have any intel I find useful, but maybe you all have a better secret decoder ring?&lt;/P&gt;
&lt;P&gt;msiexec.log:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jvcog_0-1662656539193.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21398iE83364AF864B06DF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jvcog_0-1662656539193.png" alt="jvcog_0-1662656539193.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;splunk.log:&lt;/P&gt;
&lt;P&gt;Other than a few of these types of details "input type=perfmon because it already exists" still unsure of the problem:&lt;/P&gt;
&lt;P&gt;12:51:47 PM&lt;BR /&gt;C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/outputs/tcp/server "name=REDACTED:9997" &amp;gt;&amp;gt; "C:\Users\control\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;HTTP/1.1 400 Bad Request&lt;BR /&gt;Date: Thu, 08 Sep 2022 16:51:47 GMT&lt;BR /&gt;Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;X-Content-Type-Options: nosniff&lt;BR /&gt;Content-Length: 170&lt;BR /&gt;Connection: Close&lt;BR /&gt;X-Frame-Options: SAMEORIGIN&lt;BR /&gt;Server: Splunkd&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;response&amp;gt;&lt;BR /&gt;&amp;lt;messages&amp;gt;&lt;BR /&gt;&amp;lt;msg type="ERROR"&amp;gt;REDACTED:9997 forwarded-server already present&amp;lt;/msg&amp;gt;&lt;BR /&gt;&amp;lt;/messages&amp;gt;&lt;BR /&gt;&amp;lt;/response&amp;gt;&lt;BR /&gt;12:51:47 PM&lt;BR /&gt;C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-event-log-collections/localhost lookup_host=localhost^&amp;amp;logs=Application^&amp;amp;logs=Security^&amp;amp;logs=System^&amp;amp;logs=ForwardedEvents^&amp;amp;logs=Setup &amp;gt;&amp;gt; "C:\Users\control\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;HTTP/1.1 200 OK&lt;BR /&gt;Date: Thu, 08 Sep 2022 16:51:49 GMT&lt;BR /&gt;Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;X-Content-Type-Options: nosniff&lt;BR /&gt;Content-Length: 4477&lt;BR /&gt;Connection: Close&lt;BR /&gt;X-Frame-Options: SAMEORIGIN&lt;BR /&gt;Server: Splunkd&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;!--This is to override browser formatting; see server.conf[httpServer] to disable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .--&amp;gt;&lt;BR /&gt;&amp;lt;?xml-stylesheet type="text/xml" href="/static/atom.xsl"?&amp;gt;&lt;BR /&gt;&amp;lt;feed xmlns="&lt;A href="http://www.w3.org/2005/Atom" target="_blank" rel="noopener"&gt;http://www.w3.org/2005/Atom&lt;/A&gt;" xmlns:s="&lt;A href="http://dev.splunk.com/ns/rest" target="_blank" rel="noopener"&gt;http://dev.splunk.com/ns/rest&lt;/A&gt;" xmlns:opensearch="&lt;A href="http://a9.com/-/spec/opensearch/1.1/" target="_blank" rel="noopener"&gt;http://a9.com/-/spec/opensearch/1.1/&lt;/A&gt;"&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;win-event-log-collections&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;id&amp;gt;/servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-event-log-collections&amp;lt;/id&amp;gt;&lt;BR /&gt;&amp;lt;updated&amp;gt;2022-09-08T12:51:49-04:00&amp;lt;/updated&amp;gt;&lt;BR /&gt;&amp;lt;generator build="6818ac46f2ec" version="9.0.0"/&amp;gt;&lt;BR /&gt;&amp;lt;author&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;Splunk&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;/author&amp;gt;&lt;BR /&gt;&amp;lt;link href="/servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-event-log-collections/_new" rel="create"/&amp;gt;&lt;BR /&gt;&amp;lt;link href="/servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-event-log-collections/_reload" rel="_reload"/&amp;gt;&lt;BR /&gt;&amp;lt;link href="/servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-event-log-collections/_acl" rel="_acl"/&amp;gt;&lt;BR /&gt;&amp;lt;opensearch:totalResults&amp;gt;1&amp;lt;/opensearch:totalResults&amp;gt;&lt;BR /&gt;&amp;lt;opensearch:itemsPerPage&amp;gt;30&amp;lt;/opensearch:itemsPerPage&amp;gt;&lt;BR /&gt;&amp;lt;opensearch:startIndex&amp;gt;0&amp;lt;/opensearch:startIndex&amp;gt;&lt;BR /&gt;&amp;lt;s:messages/&amp;gt;&lt;BR /&gt;&amp;lt;entry&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;localhost&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;id&amp;gt;/servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-event-log-collections/localhost&amp;lt;/id&amp;gt;&lt;BR /&gt;&amp;lt;updated&amp;gt;1969-12-31T19:00:00-05:00&amp;lt;/updated&amp;gt;&lt;BR /&gt;&amp;lt;link href="/servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-event-log-collections/localhost" rel="alternate"/&amp;gt;&lt;BR /&gt;&amp;lt;author&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;nobody&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;/author&amp;gt;&lt;BR /&gt;&amp;lt;link href="/servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-event-log-collections/localhost" rel="list"/&amp;gt;&lt;BR /&gt;&amp;lt;link href="/servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-event-log-collections/localhost/_reload" rel="_reload"/&amp;gt;&lt;BR /&gt;&amp;lt;link href="/servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-event-log-collections/localhost" rel="edit"/&amp;gt;&lt;BR /&gt;&amp;lt;content type="text/xml"&amp;gt;&lt;BR /&gt;&amp;lt;s:dict&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="disabled"&amp;gt;0&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="eai:acl"&amp;gt;&lt;BR /&gt;&amp;lt;s:dict&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="app"&amp;gt;SplunkUniversalForwarder&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="can_list"&amp;gt;1&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="can_write"&amp;gt;1&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="modifiable"&amp;gt;0&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="owner"&amp;gt;nobody&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="perms"&amp;gt;&lt;BR /&gt;&amp;lt;s:dict&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="read"&amp;gt;&lt;BR /&gt;&amp;lt;s:list&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;admin&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;power&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;splunk-system-role&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;user&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;/s:list&amp;gt;&lt;BR /&gt;&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="write"&amp;gt;&lt;BR /&gt;&amp;lt;s:list&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;admin&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;splunk-system-role&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;/s:list&amp;gt;&lt;BR /&gt;&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;/s:dict&amp;gt;&lt;BR /&gt;&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="removable"&amp;gt;1&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="sharing"&amp;gt;app&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;/s:dict&amp;gt;&lt;BR /&gt;&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="hosts"&amp;gt;localhost&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="index"&amp;gt;default&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="logs"&amp;gt;&lt;BR /&gt;&amp;lt;s:list&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;Application&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;ForwardedEvents&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;Security&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;Setup&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;s:item&amp;gt;System&amp;lt;/s:item&amp;gt;&lt;BR /&gt;&amp;lt;/s:list&amp;gt;&lt;BR /&gt;&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="lookup_host"&amp;gt;localhost&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;s:key name="name"&amp;gt;localhost&amp;lt;/s:key&amp;gt;&lt;BR /&gt;&amp;lt;/s:dict&amp;gt;&lt;BR /&gt;&amp;lt;/content&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;BR /&gt;&amp;lt;/feed&amp;gt;&lt;BR /&gt;12:51:49 PM&lt;BR /&gt;C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-perfmon "name=CPU%20Load&amp;amp;interval=10&amp;amp;object=Processor&amp;amp;counters=%25%20Processor%20Time%3B%25%20User%20Time&amp;amp;instances=_Total" &amp;gt;&amp;gt; "C:\Users\control\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;HTTP/1.1 400 Bad Request&lt;BR /&gt;Date: Thu, 08 Sep 2022 16:51:51 GMT&lt;BR /&gt;Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;X-Content-Type-Options: nosniff&lt;BR /&gt;Content-Length: 199&lt;BR /&gt;Connection: Close&lt;BR /&gt;X-Frame-Options: SAMEORIGIN&lt;BR /&gt;Server: Splunkd&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;response&amp;gt;&lt;BR /&gt;&amp;lt;messages&amp;gt;&lt;BR /&gt;&amp;lt;msg type="ERROR"&amp;gt;Cannot create object id=CPU Load of input type=perfmon because it already exists.&amp;lt;/msg&amp;gt;&lt;BR /&gt;&amp;lt;/messages&amp;gt;&lt;BR /&gt;&amp;lt;/response&amp;gt;&lt;BR /&gt;12:51:51 PM&lt;BR /&gt;C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-perfmon "name=Available%20Memory&amp;amp;interval=10&amp;amp;object=Memory&amp;amp;counters=Available%20Bytes" &amp;gt;&amp;gt; "C:\Users\control\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;HTTP/1.1 400 Bad Request&lt;BR /&gt;Date: Thu, 08 Sep 2022 16:51:52 GMT&lt;BR /&gt;Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;X-Content-Type-Options: nosniff&lt;BR /&gt;Content-Length: 207&lt;BR /&gt;Connection: Close&lt;BR /&gt;X-Frame-Options: SAMEORIGIN&lt;BR /&gt;Server: Splunkd&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;response&amp;gt;&lt;BR /&gt;&amp;lt;messages&amp;gt;&lt;BR /&gt;&amp;lt;msg type="ERROR"&amp;gt;Cannot create object id=Available Memory of input type=perfmon because it already exists.&amp;lt;/msg&amp;gt;&lt;BR /&gt;&amp;lt;/messages&amp;gt;&lt;BR /&gt;&amp;lt;/response&amp;gt;&lt;BR /&gt;12:51:52 PM&lt;BR /&gt;C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-perfmon "name=Free%20Disk%20Space&amp;amp;interval=3600&amp;amp;object=LogicalDisk&amp;amp;instances=_Total&amp;amp;counters=Free%20Megabytes%3B%25%20Free%20Space" &amp;gt;&amp;gt; "C:\Users\control\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;HTTP/1.1 400 Bad Request&lt;BR /&gt;Date: Thu, 08 Sep 2022 16:51:54 GMT&lt;BR /&gt;Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;X-Content-Type-Options: nosniff&lt;BR /&gt;Content-Length: 206&lt;BR /&gt;Connection: Close&lt;BR /&gt;X-Frame-Options: SAMEORIGIN&lt;BR /&gt;Server: Splunkd&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;response&amp;gt;&lt;BR /&gt;&amp;lt;messages&amp;gt;&lt;BR /&gt;&amp;lt;msg type="ERROR"&amp;gt;Cannot create object id=Free Disk Space of input type=perfmon because it already exists.&amp;lt;/msg&amp;gt;&lt;BR /&gt;&amp;lt;/messages&amp;gt;&lt;BR /&gt;&amp;lt;/response&amp;gt;&lt;BR /&gt;12:51:54 PM&lt;BR /&gt;C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/inputs/win-perfmon "name=Network%20Interface&amp;amp;interval=10&amp;amp;object=Network%20Interface&amp;amp;counters=Bytes%20Received%2Fsec%3BBytes%20Sent%2Fsec&amp;amp;instances=*" &amp;gt;&amp;gt; "C:\Users\control\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;HTTP/1.1 400 Bad Request&lt;BR /&gt;Date: Thu, 08 Sep 2022 16:51:56 GMT&lt;BR /&gt;Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;X-Content-Type-Options: nosniff&lt;BR /&gt;Content-Length: 208&lt;BR /&gt;Connection: Close&lt;BR /&gt;X-Frame-Options: SAMEORIGIN&lt;BR /&gt;Server: Splunkd&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;response&amp;gt;&lt;BR /&gt;&amp;lt;messages&amp;gt;&lt;BR /&gt;&amp;lt;msg type="ERROR"&amp;gt;Cannot create object id=Network Interface of input type=perfmon because it already exists.&amp;lt;/msg&amp;gt;&lt;BR /&gt;&amp;lt;/messages&amp;gt;&lt;BR /&gt;&amp;lt;/response&amp;gt;&lt;BR /&gt;12:51:56 PM&lt;BR /&gt;C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/admin/deploymentclient/deployment-client targetUri=REDACTED:8089 &amp;gt;&amp;gt; "C:\Users\control\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;HTTP/1.1 200 OK&lt;BR /&gt;Date: Thu, 08 Sep 2022 16:51:56 GMT&lt;BR /&gt;Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;X-Content-Type-Options: nosniff&lt;BR /&gt;Content-Length: 1832&lt;BR /&gt;Connection: Close&lt;BR /&gt;X-Frame-Options: SAMEORIGIN&lt;BR /&gt;Server: Splunkd&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;!--This is to override browser formatting; see server.conf[httpServer] to disable&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 07:53:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612450#M11887</guid>
      <dc:creator>jvcog</dc:creator>
      <dc:date>2022-09-09T07:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder 9 Setup Ended Prematurely on Server 2019</title>
      <link>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612500#M11891</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249290"&gt;@jvcog&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand: do you want to upgrade your UF to the last version?&lt;/P&gt;&lt;P&gt;If yes, did you tried to uninstall the previous version (manually cleaning, after uninstall, the installation folder)?&lt;/P&gt;&lt;P&gt;If yes, I hint to open a Case to Splunk Support.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 05:04:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612500#M11891</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-09T05:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder 9 Setup Ended Prematurely on Server 2019</title>
      <link>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612562#M11892</link>
      <description>&lt;P&gt;No this is a fresh install on a newly built domain controller, but the logs indicate it's running as an upgrade.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 11:51:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612562#M11892</guid>
      <dc:creator>jvcog</dc:creator>
      <dc:date>2022-09-09T11:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder 9 Setup Ended Prematurely on Server 2019</title>
      <link>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612563#M11893</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249290"&gt;@jvcog&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;see if there's something not completely installed and remove it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 12:26:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612563#M11893</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-09T12:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: How do I fix this error: Universal Forwarder 9 Setup Ended Prematurely on Server 2019?</title>
      <link>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612567#M11894</link>
      <description>&lt;P&gt;Thanks for the follow up.&amp;nbsp; I have checked and there are no indications of lingering installations.&amp;nbsp; However, I imagine there must be something in the registry that is flagging the installer but I will not haphazardly remove any "splunk" mentions from my Domain Controller registry until Splunk indicates exactly which HKEY paths to check and are safe to delete.&amp;nbsp; Do you have any suggestions of registry keys and or folders that need to be removed before proceeding with a new attempt to install?&amp;nbsp; Should I just open a support ticket and have official support address this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 12:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612567#M11894</guid>
      <dc:creator>jvcog</dc:creator>
      <dc:date>2022-09-09T12:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: How do I fix this error: Universal Forwarder 9 Setup Ended Prematurely on Server 2019?</title>
      <link>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612569#M11895</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249290"&gt;@jvcog&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes it's better to&amp;nbsp;&lt;SPAN&gt;open a support ticket and have official support address this issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Tell me if I can help you more, otherwise, please, accept any answer for the other people of Community.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 12:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-do-I-fix-this-error-Universal-Forwarder-9-Setup-Ended/m-p/612569#M11895</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-09T12:43:11Z</dc:date>
    </item>
  </channel>
</rss>

