<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Powershell Universal Forwarder Installation not working. in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644646#M12901</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251035"&gt;@jmancyber&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Oh dear.&amp;nbsp; Is this an upgrade?&amp;nbsp; Does this file exist: C:\IntunePacker\SourceSplunk\splunkforwarder.msi?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;</description>
    <pubDate>Thu, 25 May 2023 14:33:46 GMT</pubDate>
    <dc:creator>jho-splunk</dc:creator>
    <dc:date>2023-05-25T14:33:46Z</dc:date>
    <item>
      <title>Powershell Universal Forwarder Installation not working?</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644559#M12896</link>
      <description>&lt;P&gt;I'm trying to test the installation of a uf on my windows device for later deployment for work, but the script just doesn't seem to take into account the flags I specify.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;msiexec.exe /i "splunkforwarder.msi" AGREETOLICENSE=yes SPLUNKUSERNAME=Admin SPLUNKPASSWORD=Password /qn&lt;/P&gt;
&lt;P&gt;If I take out the /qn it will just open the normal UF install wizard.&lt;/P&gt;
&lt;P&gt;I'm not sure what's going on. I feel as though everything is correct.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 09:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644559#M12896</guid>
      <dc:creator>jmancyber</dc:creator>
      <dc:date>2023-05-25T09:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell Universal Forwarder Installation not working.</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644560#M12897</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251035"&gt;@jmancyber&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Have you tried enabling logging (something like: /l*vx msiexec.log)?&amp;nbsp; Does it acknowledge those parameters as being set?&amp;nbsp; What's the last thing it does just before it fails (search for "return value 3").&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 22:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644560#M12897</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2023-05-24T22:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell Universal Forwarder Installation not working.</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644561#M12898</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225785"&gt;@jho-splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So as I was looking at the logs, I saw there was an error with both password complexity and I wasn't running from an admin powershell. Here is what I now get after the large&amp;nbsp; block of "cached product context" logs&lt;/P&gt;&lt;P&gt;MSI (s) (54:10) [19:15:44:938]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038&lt;BR /&gt;MSI (s) (54:10) [19:15:44:938]: SRSetRestorePoint skipped for this transaction.&lt;BR /&gt;MSI (s) (54:10) [19:15:44:947]: Note: 1: 1309 2: 5 3: C:\IntunePacker\SourceSplunk\splunkforwarder.msi&lt;BR /&gt;MSI (s) (54:10) [19:15:44:947]: MainEngineThread is returning 110&lt;BR /&gt;MSI (s) (54:20) [19:15:44:947]: No System Restore sequence number for this installation.&lt;BR /&gt;The system cannot open the device or file specified.&lt;BR /&gt;MSI (s) (54:20) [19:15:44:947]: User policy value 'DisableRollback' is 0&lt;BR /&gt;MSI (s) (54:20) [19:15:44:947]: Machine policy value 'DisableRollback' is 0&lt;BR /&gt;MSI (s) (54:20) [19:15:44:947]: Incrementing counter to disable shutdown. Counter after increment: 0&lt;BR /&gt;MSI (s) (54:20) [19:15:44:947]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2&lt;BR /&gt;MSI (s) (54:20) [19:15:44:947]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2&lt;BR /&gt;MSI (s) (54:20) [19:15:44:947]: Decrementing counter to disable shutdown. If counter &amp;gt;= 0, shutdown will be denied. Counter after decrement: -1&lt;BR /&gt;MSI (c) (4C:6C) [19:15:44:947]: Decrementing counter to disable shutdown. If counter &amp;gt;= 0, shutdown will be denied. Counter after decrement: -1&lt;BR /&gt;MSI (c) (4C:6C) [19:15:44:947]: MainEngineThread is returning 110&lt;BR /&gt;=== Verbose logging stopped: 5/24/2023 19:15:44 ===&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 23:20:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644561#M12898</guid>
      <dc:creator>jmancyber</dc:creator>
      <dc:date>2023-05-24T23:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell Universal Forwarder Installation not working.</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644629#M12899</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225785"&gt;@jho-splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So upon looking at those logs I saw that I had to run as admin and my password complexity needed to be more robust. After fixing this it still doesn't seem to work and I get the following after the command runs(deleted most of the cached product context logs for character limits sake):&lt;/P&gt;&lt;P&gt;=== Verbose logging started: 5/25/2023 9:15:43 Build type: SHIP UNICODE 5.00.10011.00 Calling process: C:\Windows\system32\msiexec.exe ===&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:676]: Resetting cached policy values&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:676]: Machine policy value 'Debug' is 0&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:676]: ******* RunEngine:&lt;BR /&gt;******* Product: splunkforwarder.msi&lt;BR /&gt;******* Action:&lt;BR /&gt;******* CommandLine: **********&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:676]: Client-side and UI is none or basic: Running entire install on the server.&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:676]: Grabbed execution mutex.&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:692]: Cloaking enabled.&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:692]: Attempting to enable all disabled privileges before calling Install on Server&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:692]: Incrementing counter to disable shutdown. Counter after increment: 0&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:692]: Running installation inside multi-package transaction C:\IntunePacker\SourceSplunk\splunkforwarder.msi&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:692]: Grabbed execution mutex.&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:692]: Resetting cached policy values&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:692]: Machine policy value 'Debug' is 0&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:692]: ******* RunEngine:&lt;BR /&gt;******* Product: C:\IntunePacker\SourceSplunk\splunkforwarder.msi&lt;BR /&gt;******* Action:&lt;BR /&gt;******* CommandLine: **********&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: Using cached product context: machine assigned for product: F60730A4A66673047777F5728467D401&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: Setting cached product context: machine assigned for product: FC5DAE63FE44FCF4B81E9DC684537D4A&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: Using cached product context: machine assigned for product: FC5DAE63FE44FCF4B81E9DC684537D4A&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: Setting cached product context: machine assigned for product: FD59EB73A00F35141B2F80DB1735642E&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: Using cached product context: machine assigned for product: FD59EB73A00F35141B2F80DB1735642E&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: Setting cached product context: machine assigned for product: FE2CADEB2ABD52B458A7D73F58AF46E5&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: Using cached product context: machine assigned for product: FE2CADEB2ABD52B458A7D73F58AF46E5&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: SRSetRestorePoint skipped for this transaction.&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: Note: 1: 1309 2: 5 3: C:\IntunePacker\SourceSplunk\splunkforwarder.msi&lt;BR /&gt;MSI (s) (1C:14) [09:15:43:708]: MainEngineThread is returning 110&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: No System Restore sequence number for this installation.&lt;BR /&gt;The system cannot open the device or file specified.&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: User policy value 'DisableRollback' is 0&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: Machine policy value 'DisableRollback' is 0&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: Incrementing counter to disable shutdown. Counter after increment: 0&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: Decrementing counter to disable shutdown. If counter &amp;gt;= 0, shutdown will be denied. Counter after decrement: -1&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:723]: Decrementing counter to disable shutdown. If counter &amp;gt;= 0, shutdown will be denied. Counter after decrement: -1&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:723]: MainEngineThread is returning 110&lt;BR /&gt;=== Verbose logging stopped: 5/25/2023 9:15:43 ===&lt;BR /&gt;&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: Machine policy value 'DisableRollback' is 0&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: Incrementing counter to disable shutdown. Counter after increment: 0&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2&lt;BR /&gt;MSI (s) (1C:58) [09:15:43:723]: Decrementing counter to disable shutdown. If counter &amp;gt;= 0, shutdown will be denied. Counter after decrement: -1&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:723]: Decrementing counter to disable shutdown. If counter &amp;gt;= 0, shutdown will be denied. Counter after decrement: -1&lt;BR /&gt;MSI (c) (C0:90) [09:15:43:723]: MainEngineThread is returning 110&lt;BR /&gt;=== Verbose logging stopped: 5/25/2023 9:15:43 ===&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 13:19:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644629#M12899</guid>
      <dc:creator>jmancyber</dc:creator>
      <dc:date>2023-05-25T13:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell Universal Forwarder Installation not working.</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644633#M12900</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225785"&gt;@jho-splunk&lt;/a&gt;,&lt;/P&gt;&lt;P class="lia-align-right"&gt;I enabled logging and saw there was an error with my password complexity and I needed to run as admin, upon doing so it still doesn't seem to work.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmancyber_0-1685020996773.png" style="width: 675px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25541iCE6A39AC5A2D3F91/image-dimensions/675x248?v=v2" width="675" height="248" role="button" title="jmancyber_0-1685020996773.png" alt="jmancyber_0-1685020996773.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 13:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644633#M12900</guid>
      <dc:creator>jmancyber</dc:creator>
      <dc:date>2023-05-25T13:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell Universal Forwarder Installation not working.</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644646#M12901</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251035"&gt;@jmancyber&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Oh dear.&amp;nbsp; Is this an upgrade?&amp;nbsp; Does this file exist: C:\IntunePacker\SourceSplunk\splunkforwarder.msi?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 14:33:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644646#M12901</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2023-05-25T14:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell Universal Forwarder Installation not working.</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644648#M12902</link>
      <description>&lt;P&gt;Oh nope it's&amp;nbsp; a completely fresh install, just testing for future deployment and that was the folder I have it in. The msi is a file straight off of the splunk download page and I am running straight from file the msi is found in.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 14:45:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644648#M12902</guid>
      <dc:creator>jmancyber</dc:creator>
      <dc:date>2023-05-25T14:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell Universal Forwarder Installation not working.</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644656#M12903</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251035"&gt;@jmancyber&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Well, it looks like msiexec.exe doesn't think it exists.&amp;nbsp; Are you maybe assuming something about the current working directory that may not be true?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 15:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/644656#M12903</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2023-05-25T15:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell Universal Forwarder Installation not working.</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/645292#M12920</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225785"&gt;@jho-splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Apologies for the late response, got caught up in work. I figured out that the file I had been trying to run was being automatically protected which was fixed by simply going into the properties and unchecking a box. From there everything was fixed I appreciate the help as the info found from looking into the logs helped tremendously with weeding out the other issues!&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;-J&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 18:09:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/645292#M12920</guid>
      <dc:creator>jmancyber</dc:creator>
      <dc:date>2023-05-31T18:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: Powershell Universal Forwarder Installation not working.</title>
      <link>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/645644#M12943</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251035"&gt;@jmancyber&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Oh, that's a great find.&amp;nbsp; Thanks for reporting back, it's always helpful!&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jun 2023 22:55:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Powershell-Universal-Forwarder-Installation-not-working/m-p/645644#M12943</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2023-06-03T22:55:49Z</dc:date>
    </item>
  </channel>
</rss>

