<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New Install of Splunk - Rollback occurs near the end of install negating install? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612893#M11907</link>
    <description>&lt;P&gt;first_install.log contains 4 lines that just list the version, build, product and platform.&amp;nbsp; Its Windows Server 2019.&amp;nbsp; The VM&amp;nbsp; has 4 CPU and 24GB of memory.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Sep 2022 13:35:59 GMT</pubDate>
    <dc:creator>trtracy</dc:creator>
    <dc:date>2022-09-13T13:35:59Z</dc:date>
    <item>
      <title>New Install of Splunk - Rollback occurs near the end of install negating install?</title>
      <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612800#M11903</link>
      <description>&lt;P&gt;Brand new VM server.&amp;nbsp; Fresh copy of Splunk 9.0 install file.&amp;nbsp; Running installer with elevated privileges.&amp;nbsp;&amp;nbsp; Selecting Domain Account option in wizard.&amp;nbsp; Account used is member of Domain Admins.&amp;nbsp; Account listed in Security Policy as member to Allow Login Locally. Generated log file for install but nothing in it shows a error.&amp;nbsp; All these were suggestions to look at if install is not working that I found online.&amp;nbsp; Yet, it still fails doing the install and does a rollback.&amp;nbsp; Any other suggestions?&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 12:51:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612800#M11903</guid>
      <dc:creator>trtracy</dc:creator>
      <dc:date>2022-09-13T12:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: New Install of Splunk - Rollback occurs near the end of install negating install.</title>
      <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612826#M11904</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249399"&gt;@trtracy&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;what's your Windows OS?&lt;/P&gt;&lt;P&gt;What does the installation log contain ($SPLUNK_HOME\var\log\splunk\first_install.log)?&lt;/P&gt;&lt;P&gt;if it's one of the Splunk supported (&lt;SPAN&gt;Windows 10,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Windows Server 2016, 2019, 2022,&amp;nbsp;&lt;/SPAN&gt;you can see this at &lt;A href="https://www.splunk.com/en_us/download/splunk-enterprise.html" target="_blank"&gt;https://www.splunk.com/en_us/download/splunk-enterprise.html&lt;/A&gt;), the only way is opening a Case to the Splunk Support sending them the installation log.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 06:27:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612826#M11904</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-13T06:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: New Install of Splunk - Rollback occurs near the end of install negating install.</title>
      <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612872#M11906</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249399"&gt;@trtracy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Please see the following reply for instructions on how to troubleshoot:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540173/highlight/true#M7187" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540173/highlight/true#...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 11:54:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612872#M11906</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2022-09-13T11:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: New Install of Splunk - Rollback occurs near the end of install negating install?</title>
      <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612893#M11907</link>
      <description>&lt;P&gt;first_install.log contains 4 lines that just list the version, build, product and platform.&amp;nbsp; Its Windows Server 2019.&amp;nbsp; The VM&amp;nbsp; has 4 CPU and 24GB of memory.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 13:35:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612893#M11907</guid>
      <dc:creator>trtracy</dc:creator>
      <dc:date>2022-09-13T13:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: New Install of Splunk - Rollback occurs near the end of install negating install?</title>
      <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612900#M11908</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249399"&gt;@trtracy&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;your Hardware dotation isn't correct, Splunk requires at least 12 CPUs and 12 GB RAM.&lt;/P&gt;&lt;P&gt;This shouldn't be relevant for the installation that should run without problems, it's only relevant in normal running or if you try to open a case to Splunk Support and probably you'll have to do it.&lt;/P&gt;&lt;P&gt;I hint to call Splunk Support.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 14:21:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612900#M11908</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-13T14:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: New Install of Splunk - Rollback occurs near the end of install negating install?</title>
      <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612903#M11909</link>
      <description>&lt;P&gt;Changed to 12 CPU's and 16GB memory.&amp;nbsp; Same issue.&amp;nbsp; I think its a permission issue but the logs are not telling me much.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 14:50:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612903#M11909</guid>
      <dc:creator>trtracy</dc:creator>
      <dc:date>2022-09-13T14:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: New Install of Splunk - Rollback occurs near the end of install negating install.</title>
      <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612904#M11910</link>
      <description>&lt;P&gt;MSI (s) (A8!58) [08:34:26:146]: Closing MSIHANDLE (279) of type 790531 for thread 6232&lt;BR /&gt;MSI (s) (A8:E4) [08:34:26:161]: Closing MSIHANDLE (259) of type 790536 for thread 5160&lt;BR /&gt;MSI (s) (A8:28) [08:34:26:161]: Executing op: ActionStart(Name=SetupServiceConfig,,)&lt;BR /&gt;Action 8:34:26: SetupServiceConfig.&lt;BR /&gt;MSI (s) (A8:28) [08:34:26:161]: Executing op: CustomActionSchedule(Action=SetupServiceConfig,ActionType=11265,Source=BinaryData,Target=**********,CustomActionData=**********)&lt;BR /&gt;MSI (s) (A8:28) [08:34:26:161]: Creating MSIHANDLE (280) of type 790536 for thread 5160&lt;BR /&gt;MSI (s) (A8:24) [08:34:26:161]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI6F52.tmp, Entrypoint: SetupServiceConfigCA&lt;BR /&gt;MSI (s) (A8!68) [08:34:26:286]: Creating MSIHANDLE (281) of type 790531 for thread 3176&lt;BR /&gt;SetupServiceConfig: Warning: Invalid property ignored: EnableApp=.&lt;BR /&gt;MSI (s) (A8!68) [08:34:26:286]: Closing MSIHANDLE (281) of type 790531 for thread 3176&lt;BR /&gt;MSI (s) (A8!68) [08:34:26:286]: Creating MSIHANDLE (282) of type 790531 for thread 3176&lt;BR /&gt;SetupServiceConfig: Warning: Invalid property ignored: FailCA=.&lt;BR /&gt;MSI (s) (A8!68) [08:34:26:286]: Closing MSIHANDLE (282) of type 790531 for thread 3176&lt;BR /&gt;MSI (s) (A8!68) [08:34:26:286]: Creating MSIHANDLE (283) of type 790531 for thread 3176&lt;BR /&gt;SetupServiceConfig: Error: ChangeServiceConfig failed 0x421&lt;BR /&gt;MSI (s) (A8!68) [08:34:26:286]: Closing MSIHANDLE (283) of type 790531 for thread 3176&lt;BR /&gt;MSI (s) (A8!68) [08:34:26:286]: Creating MSIHANDLE (284) of type 790531 for thread 3176&lt;BR /&gt;SetupServiceConfig: Error 0x80004005: Cannot setup splunkd service.&lt;BR /&gt;MSI (s) (A8!68) [08:34:26:286]: Closing MSIHANDLE (284) of type 790531 for thread 3176&lt;BR /&gt;CustomAction SetupServiceConfig returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)&lt;BR /&gt;MSI (s) (A8:24) [08:34:26:286]: Closing MSIHANDLE (280) of type 790536 for thread 5160&lt;BR /&gt;Action ended 8:34:26: InstallFinalize. Return value 3.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 14:54:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612904#M11910</guid>
      <dc:creator>trtracy</dc:creator>
      <dc:date>2022-09-13T14:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: New Install of Splunk - Rollback occurs near the end of install negating install?</title>
      <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612905#M11911</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249399"&gt;@trtracy&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said hardware isn't relevant for the problem, but now you can open a case to Splunk Support.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 15:00:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/612905#M11911</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-13T15:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: New Install of Splunk - Rollback occurs near the end of install negating install.</title>
      <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/613075#M11917</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249399"&gt;@trtracy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Aha!&lt;/P&gt;&lt;PRE&gt;&amp;gt; net helpmsg (0x421)&lt;BR /&gt;&lt;BR /&gt;The account name is invalid or does not exist, or the password is invalid for the account name specified.&lt;/PRE&gt;&lt;P&gt;So the logon username and/or password are incorrect.&amp;nbsp; Are you supplying the full domain user account name (e.g., "ACMECORP\splunk-service" and not just "splunk-service")?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 13:11:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/613075#M11917</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2022-09-14T13:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: New Install of Splunk - Rollback occurs near the end of install negating install.</title>
      <link>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/613083#M11918</link>
      <description>&lt;P&gt;When I supply the domain name I&amp;nbsp; get invalid account on the dialog box prompting for this information.&amp;nbsp; I assumed this field for the account name did not like a slash in the name so I continued without it because it went on to the next screen without it.&amp;nbsp; I assumed incorrectly again that if I'm using the same account to log into the computer that I'm using in this field for the install, it would know I'm a member of that domain.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I just tested was adding .local to the end of the domain name and worked.&amp;nbsp; Thank you for finding the solution.&amp;nbsp; Funny on how some things you do in windows only need the domain name while others need the TLD extension as well such as in this case.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 13:58:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Install-of-Splunk-Rollback-occurs-near-the-end-of-install/m-p/613083#M11918</guid>
      <dc:creator>trtracy</dc:creator>
      <dc:date>2022-09-14T13:58:38Z</dc:date>
    </item>
  </channel>
</rss>

