<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does Splunk upgrade to version 9.1.0.1 ends prematurely? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652791#M13133</link>
    <description>&lt;P&gt;looks like people were having the same problem six years ago&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Building-for-the-Splunk-Platform/Rollback-during-Installation-Windows-64-bit/m-p/335020/highlight/false#M4994" target="_blank"&gt;https://community.splunk.com/t5/Building-for-the-Splunk-Platform/Rollback-during-Installation-Windows-64-bit/m-p/335020/highlight/false#M4994&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2023 01:12:49 GMT</pubDate>
    <dc:creator>Gregski11</dc:creator>
    <dc:date>2023-08-02T01:12:49Z</dc:date>
    <item>
      <title>Why does Splunk upgrade to version 9.1.0.1 end prematurely?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652577#M13118</link>
      <description>&lt;P&gt;trying to upgrade our Windows Server 2019 based Splunk version 9.0.0 to&amp;nbsp;9.1.0.1 and it's randomly failing on 50% or half of our 12 servers in our lab&lt;/P&gt;&lt;P&gt;the error below is from one of our non clustered Search Heads, others which are identical installed fine, we got the same error on our index Cluster Master&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Splunk Enterprise Setup Wizard ended prematurely&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Splunk Enterprise Setup Wizard ended prematurely because of an error.&amp;nbsp; Your system has not been modified.&amp;nbsp; To install this program at a later time, run Setup Wizard again.&amp;nbsp; Click the Fiinish button to exit the Setup Wizard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gregski11_0-1690829549621.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26549i3275882B57A56DCF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gregski11_0-1690829549621.png" alt="Gregski11_0-1690829549621.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gregski11_1-1690829684601.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26550iB646B7E0841464B6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gregski11_1-1690829684601.png" alt="Gregski11_1-1690829684601.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup cannot copy the following files:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splknetdrv.sys&lt;BR /&gt;SplunkMonitorNoHandleDrv.sys&lt;BR /&gt;SplunkDrv.sys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gregski11_0-1690982720173.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26605i4548BD3673DF16E1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gregski11_0-1690982720173.png" alt="Gregski11_0-1690982720173.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gregski11_1-1690982732446.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26606iD0B74D1CC57CADED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gregski11_1-1690982732446.png" alt="Gregski11_1-1690982732446.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gregski11_2-1690982742793.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26607i6E9AE381D30BF50C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gregski11_2-1690982742793.png" alt="Gregski11_2-1690982742793.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 13:25:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652577#M13118</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2023-08-02T13:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk upgrade to version 9.1.0.1 ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652578#M13119</link>
      <description>&lt;P&gt;Launch it with verbose logging and check the logfile for errors/warnings&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/Installation/InstallonWindowsviathecommandline#Install_Splunk_Enterprise_with_verbose_logging_to_C:.5CTEMP.5CSplunkInstall.log" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.0/Installation/InstallonWindowsviathecommandline#Install_Splunk_Enterprise_with_verbose_logging_to_C:.5CTEMP.5CSplunkInstall.log&lt;/A&gt;&lt;/P&gt;&lt;P&gt;As a quick check - do your servers all run as Local System or maybe you have some permission issues?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 19:19:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652578#M13119</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-07-31T19:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk upgrade to version 9.1.0.1 ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652592#M13120</link>
      <description>&lt;P&gt;ok, did just that and here is a section from the install log where things go south and setup begins rolling back&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;MSI (s) (FC:F4) [12:47:17:625]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIF1EF.tmp, Entrypoint: StopSplunkServiceDefCA&lt;BR /&gt;MSI (s) (FC:68) [12:47:17:625]: Generating random cookie.&lt;BR /&gt;MSI (s) (FC:68) [12:47:17:625]: Created Custom Action Server with PID 2452 (0x994).&lt;BR /&gt;MSI (s) (FC:70) [12:47:17:719]: Running as a service.&lt;BR /&gt;MSI (s) (FC:70) [12:47:17:719]: Hello, I'm your 64bit Elevated Non-remapped custom action server.&lt;BR /&gt;StopSplunkServiceDef: Warning: Invalid property ignored: FailCA=.&lt;BR /&gt;StopSplunkServiceDef: Info: Properties: splunkHome: C:\Program Files\Splunk, svcName: Splunkd.&lt;BR /&gt;StopSplunkServiceDef: Info: Enter.&lt;BR /&gt;StopSplunkServiceDef: Info: service Splunkd already exists&lt;BR /&gt;StopSplunkServiceDef: Info: Leave.&lt;BR /&gt;MSI (s) (FC:F4) [12:47:17:734]: Executing op: ActionStart(Name=ReinstallRegmonDrv,,)&lt;BR /&gt;Action 12:47:17: ReinstallRegmonDrv.&lt;BR /&gt;MSI (s) (FC:F4) [12:47:17:734]: Executing op: CustomActionSchedule(Action=ReinstallRegmonDrv,ActionType=1281,Source=BinaryData,Target=InstallRegmonDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=)&lt;BR /&gt;MSI (s) (FC:F4) [12:47:17:750]: Executing op: ActionStart(Name=UninstallNetmonDrv,,)&lt;BR /&gt;Action 12:47:17: UninstallNetmonDrv.&lt;BR /&gt;MSI (s) (FC:F4) [12:47:17:750]: Executing op: CustomActionSchedule(Action=UninstallNetmonDrv,ActionType=3073,Source=BinaryData,Target=UninstallNetmonDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=)&lt;BR /&gt;MSI (s) (FC:14) [12:47:17:812]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIF2AB.tmp, Entrypoint: UninstallNetmonDrvCA&lt;BR /&gt;UninstallNetmonDrv: Warning: Invalid property ignored: FailCA=.&lt;BR /&gt;UninstallNetmonDrv: Info: Driver inf file: C:\Program Files\Splunk\bin\splknetdrv.inf.&lt;BR /&gt;UninstallNetmonDrv: Info: Enter.&lt;BR /&gt;UninstallNetmonDrv: Info: Service: splknetdrv, state: 1.&lt;BR /&gt;UninstallNetmonDrv: Info: splknetdrv service does not exists.&lt;BR /&gt;UninstallNetmonDrv: Info: Enter. Args: rundll32.exe, setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\splknetdrv.inf&lt;BR /&gt;UninstallNetmonDrv: Info: SystemPath is: C:\Windows\system32\&lt;BR /&gt;UninstallNetmonDrv: Info: Execute string: C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\splknetdrv.inf &amp;gt;&amp;gt; "C:\Users\MUSZYN~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;UninstallNetmonDrv: Info: WaitForSingleObject returned : 0x0&lt;BR /&gt;UninstallNetmonDrv: Info: Exit code for process : 0x0&lt;BR /&gt;UninstallNetmonDrv: Info: Leave.&lt;BR /&gt;MSI (s) (FC:F4) [12:47:18:390]: Executing op: ActionStart(Name=ReinstallNohandleDrv,,)&lt;BR /&gt;Action 12:47:18: ReinstallNohandleDrv.&lt;BR /&gt;MSI (s) (FC:F4) [12:47:18:390]: Executing op: CustomActionSchedule(Action=ReinstallNohandleDrv,ActionType=1281,Source=BinaryData,Target=InstallNohandleDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=)&lt;BR /&gt;MSI (s) (FC:F4) [12:47:18:390]: Executing op: ActionStart(Name=UninstallRegmonDrv,,)&lt;BR /&gt;Action 12:47:18: UninstallRegmonDrv.&lt;BR /&gt;MSI (s) (FC:F4) [12:47:18:406]: Executing op: CustomActionSchedule(Action=UninstallRegmonDrv,ActionType=3073,Source=BinaryData,Target=UninstallRegmonDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=)&lt;BR /&gt;MSI (s) (FC:50) [12:47:18:453]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIF53D.tmp, Entrypoint: UninstallRegmonDrvCA&lt;BR /&gt;UninstallRegmonDrv: Warning: Invalid property ignored: FailCA=.&lt;BR /&gt;UninstallRegmonDrv: Info: Driver inf file: C:\Program Files\Splunk\bin\splunkdrv.inf.&lt;BR /&gt;UninstallRegmonDrv: Info: Enter.&lt;BR /&gt;UninstallRegmonDrv: Info: Service: splunkdrv, state: 1.&lt;BR /&gt;UninstallRegmonDrv: Info: splunkdrv service does not exists.&lt;BR /&gt;UninstallRegmonDrv: Info: Enter. Args: rundll32.exe, setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\splunkdrv.inf&lt;BR /&gt;UninstallRegmonDrv: Info: SystemPath is: C:\Windows\system32\&lt;BR /&gt;UninstallRegmonDrv: Info: Execute string: C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\splunkdrv.inf &amp;gt;&amp;gt; "C:\Users\MUSZYN~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;UninstallRegmonDrv: Info: WaitForSingleObject returned : 0x0&lt;BR /&gt;UninstallRegmonDrv: Info: Exit code for process : 0x0&lt;BR /&gt;UninstallRegmonDrv: Info: Leave.&lt;BR /&gt;MSI (s) (FC:F4) [12:47:19:031]: Executing op: ActionStart(Name=ReinstallNetmonDrv,,)&lt;BR /&gt;Action 12:47:19: ReinstallNetmonDrv.&lt;BR /&gt;MSI (s) (FC:F4) [12:47:19:047]: Executing op: CustomActionSchedule(Action=ReinstallNetmonDrv,ActionType=1281,Source=BinaryData,Target=InstallNetmonDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=)&lt;BR /&gt;MSI (s) (FC:F4) [12:47:19:047]: Executing op: ActionStart(Name=UninstallNohandleDrv,,)&lt;BR /&gt;Action 12:47:19: UninstallNohandleDrv.&lt;BR /&gt;MSI (s) (FC:F4) [12:47:19:047]: Executing op: CustomActionSchedule(Action=UninstallNohandleDrv,ActionType=3073,Source=BinaryData,Target=UninstallNohandleDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=)&lt;BR /&gt;MSI (s) (FC:88) [12:47:19:094]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIF7BE.tmp, Entrypoint: UninstallNohandleDrvCA&lt;BR /&gt;UninstallNohandleDrv: Warning: Invalid property ignored: FailCA=.&lt;BR /&gt;UninstallNohandleDrv: Info: Driver inf file: C:\Program Files\Splunk\bin\SplunkMonitorNoHandleDrv.inf.&lt;BR /&gt;UninstallNohandleDrv: Info: Enter.&lt;BR /&gt;UninstallNohandleDrv: Info: Service: SplunkMonitorNoHandle, state: 1.&lt;BR /&gt;UninstallNohandleDrv: Info: SplunkMonitorNoHandle service does not exists.&lt;BR /&gt;UninstallNohandleDrv: Info: Enter. Args: rundll32.exe, setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\SplunkMonitorNoHandleDrv.inf&lt;BR /&gt;UninstallNohandleDrv: Info: SystemPath is: C:\Windows\system32\&lt;BR /&gt;UninstallNohandleDrv: Info: Execute string: C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\SplunkMonitorNoHandleDrv.inf &amp;gt;&amp;gt; "C:\Users\MUSZYN~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;UninstallNohandleDrv: Info: WaitForSingleObject returned : 0x0&lt;BR /&gt;UninstallNohandleDrv: Info: Exit code for process : 0x0&lt;BR /&gt;UninstallNohandleDrv: Info: Leave.&lt;BR /&gt;MSI (s) (FC:F4) [12:47:19:703]: Executing op: ActionStart(Name=RemoveFiles,Description=Removing files,Template=File: [1], Directory: [9])&lt;BR /&gt;Action 12:47:19: RemoveFiles. Removing files&lt;BR /&gt;MSI (s) (FC:F4) [12:47:19:703]: Executing op: ProgressTotal(Total=17609,Type=1,ByteEquivalent=175000)&lt;BR /&gt;MSI (s) (FC:F4) [12:47:19:703]: Executing op: SetTargetFolder(Folder=C:\ProgramData\Splunk Enterprise\)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 20:22:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652592#M13120</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2023-07-31T20:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk upgrade to version 9.1.0.1 ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652721#M13127</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232137"&gt;@Gregski11&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Everything appears be fine in the snippet you posted.&amp;nbsp; Please see here for instructions on how to troubleshoot further:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540173/highlight/true#M7187" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540173/highlight/true#M7187&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; - Jo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 14:45:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652721#M13127</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2023-08-01T14:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk upgrade to version 9.1.0.1 ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652789#M13132</link>
      <description>&lt;P&gt;Rollback: StopSplunkServiceDef&lt;BR /&gt;MSI (s) (B4:98) [22:00:59:416]: Executing op: ActionStart(Name=StopSplunkServiceDef,,)&lt;BR /&gt;Rollback: RestartSplunkService&lt;BR /&gt;MSI (s) (B4:98) [22:00:59:416]: Executing op: ActionStart(Name=RestartSplunkService,,)&lt;BR /&gt;MSI (s) (B4:98) [22:00:59:416]: Executing op: CustomActionRollback(Action=RestartSplunkService,ActionType=1281,Source=BinaryData,Target=StartSplunkServiceCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;SplunkSvcName=Splunkd;LaunchSplunk=1;FailCA=)&lt;BR /&gt;MSI (s) (B4:BC) [22:00:59:478]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIDCBF.tmp, Entrypoint: StartSplunkServiceCA&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;StartSplunkService: Warning: Invalid property ignored: FailCA=.&lt;/FONT&gt;&lt;BR /&gt;StartSplunkService: Info: Properties: splunkHome: C:\Program Files\Splunk, svcName: Splunkd, launch splunk: 1.&lt;BR /&gt;StartSplunkService: Info: Enter.&lt;BR /&gt;StartSplunkService: Info: service Splunkd already exists&lt;BR /&gt;StartSplunkService: Info: Leave.&lt;BR /&gt;StartSplunkService: Info: Enter. Args: "C:\Program Files\Splunk\bin\splunk.exe", start --answer-yes --no-prompt --accept-license --auto-ports&lt;BR /&gt;StartSplunkService: Info: SystemPath is: C:\Windows\system32\&lt;BR /&gt;StartSplunkService: Info: Execute string: C:\Windows\system32\cmd.exe /c ""C:\Program Files\Splunk\bin\splunk.exe" start --answer-yes --no-prompt --accept-license --auto-ports &amp;gt;&amp;gt; "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;StartSplunkService: Info: WaitForSingleObject returned : 0x0&lt;BR /&gt;StartSplunkService: Info: Exit code for process : 0x1&lt;BR /&gt;StartSplunkService: Info: Leave.&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;StartSplunkService: Error: ExecCmd failed: 0x1.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;StartSplunkService: Error 0x80004005: Cannot start splunkd service.&lt;/FONT&gt;&lt;BR /&gt;CustomAction RestartSplunkService returned actual error code 1603 but will be translated to success due to continue marking&lt;BR /&gt;Rollback: Updating component registration&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 00:47:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652789#M13132</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2023-08-02T00:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk upgrade to version 9.1.0.1 ends prematurely?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652791#M13133</link>
      <description>&lt;P&gt;looks like people were having the same problem six years ago&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Building-for-the-Splunk-Platform/Rollback-during-Installation-Windows-64-bit/m-p/335020/highlight/false#M4994" target="_blank"&gt;https://community.splunk.com/t5/Building-for-the-Splunk-Platform/Rollback-during-Installation-Windows-64-bit/m-p/335020/highlight/false#M4994&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 01:12:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652791#M13133</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2023-08-02T01:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk upgrade to version 9.1.0.1 ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652845#M13138</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232137"&gt;@Gregski11&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Hmmm...not much to go on there unfortunately.&amp;nbsp; Is there a %TEMP%\splunk.log?&amp;nbsp; How long does it take to fail to start?&amp;nbsp; There may be salient errors and/or warnings in splunkd.log and/or web_service.log.&amp;nbsp; If there's nothing there, then we'll probably need to resort to a Process Monitor trace, but unfortunately that's not typically very shareable here.&lt;/P&gt;&lt;P&gt;Are you on the splunk-usergroups Slack, perchance?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 09:07:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/652845#M13138</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2023-08-02T09:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk upgrade to version 9.1.0.1 end prematurely?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/654037#M13178</link>
      <description>&lt;P&gt;+1&lt;/P&gt;&lt;P&gt;having the same errors when upgrading to 9.1.0.2&lt;/P&gt;&lt;P&gt;have you solved it meanwhile ?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 09:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/654037#M13178</guid>
      <dc:creator>_alex</dc:creator>
      <dc:date>2023-08-11T09:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk upgrade to version 9.1.0.1 end prematurely?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/654162#M13182</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239729"&gt;@_alex&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Unfortunately installation failures typically end very generically so it's impossible to know what happened without more information.&lt;/P&gt;&lt;P&gt;Please see here for instructions on how to troubleshoot further:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540173/highlight/true#M7187" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540173/highlight/true#...&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; - Jo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Aug 2023 23:31:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/654162#M13182</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2023-08-12T23:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk upgrade to version 9.1.0.1 end prematurely?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/655191#M13203</link>
      <description>&lt;P&gt;I was having this issue going from 9.0.4.1 to 9.1.0.1 and had to go to PowerShell and run msiexec.exe /f&amp;nbsp; splunk-9.0.4.1 this repaired whatever was wrong with the current install to allow me to run msiexec.exe /i splunk-9.1.0.1&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 15:01:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/655191#M13203</guid>
      <dc:creator>lowcrawl</dc:creator>
      <dc:date>2023-08-22T15:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk upgrade to version 9.1.0.1 ends prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/655821#M13206</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;For which user does the installer and service work?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;It looks like the user does not have file permissions.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The installer attempts &lt;SPAN&gt;to run the SPLUNK process after installation.&lt;/SPAN&gt;&lt;SPAN&gt; If the Splunk process does not start running, the installer makes the assumption that the installation failed then the installer rolls back the installation and removes the Splunk &lt;/SPAN&gt;Enterprise instance&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you use domain user or MSA then this account does not have NTFS permissions for Splunk Enterprise installation directory. &lt;SPAN&gt;After installation, you need &lt;/SPAN&gt;explicitly assign &lt;SPAN&gt;NTFS &lt;/SPAN&gt;permissions from that directory and all subdirectories &lt;SPAN&gt;for the MSA account&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, you cannot do this during installation if you run the msi file directly, and as a result you will get the error that is mentioned above&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Solution:&lt;/P&gt;&lt;P&gt;Install Splunk from the command line and use the &lt;STRONG&gt;LAUNCHSPLUNK=0 &lt;/STRONG&gt;flag to keep Splunk Enterprise from starting after installation has completed.&lt;/P&gt;&lt;P&gt;For example :&lt;/P&gt;&lt;P&gt;PS C:\temp&amp;gt; msiexec.exe /i splunk-9.0.4-de405f4a7979-x64-release.msi LAUNCHSPLUNK=0&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;You can complete the installation, and before running SPLUNK, you need to grant the user "Full Control" permissions to the Splunk Enterprise installation directory and all of its subdirectories.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 11:13:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/655821#M13206</guid>
      <dc:creator>JuriJ</dc:creator>
      <dc:date>2023-08-28T11:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk upgrade to version 9.1.0.1 end prematurely?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/661030#M13331</link>
      <description>&lt;P&gt;I don't like abandoned threads, so after hours and hours with Splunk Tech Support and having opened multiple cases on this issue I have something worth sharing.&lt;/P&gt;&lt;P&gt;You may need to do &lt;STRONG&gt;Two things&lt;/STRONG&gt; to get this to work / install:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;First Part&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; using the command line stop Splunk from running, so run &lt;STRONG&gt;SPLUNK STOP&lt;/STRONG&gt; on Windows it may look somethign like this&lt;BR /&gt;&lt;BR /&gt;C:\Program Files\Splunk\bin&amp;gt;&lt;STRONG&gt;splunk stop&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;2. then run the install MSI with the &lt;STRONG&gt;LAUNCHSPLUNK=0&lt;/STRONG&gt; parameter (no it does not have to be all in caps, not on Windows anyways)&lt;BR /&gt;&lt;BR /&gt;C:\Software\Splunk&amp;gt;&lt;STRONG&gt;splunk-9.1.1-64e843ea36b1-x64-release.msi launchsplunk=0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alright, that may get it installed, but afterwards you will notice it does not want to start, but that's ok, I will show you what to do to get it to start in the follow up post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 14:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/661030#M13331</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2023-10-17T14:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk upgrade to version 9.1.0.1 end prematurely?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/693789#M14065</link>
      <description>&lt;P&gt;Hi Gregski,&lt;/P&gt;&lt;P&gt;I was able to get Splunk to install via your steps, but it wont start as you mentioned. What steps do I need to do to get the SplunkD service to start. Currently i get a timeout error when attempting to start it via CLI&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 19:07:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/693789#M14065</guid>
      <dc:creator>MKhan1</dc:creator>
      <dc:date>2024-07-18T19:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk upgrade to version 9.1.0.1 end prematurely?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/744517#M14357</link>
      <description>&lt;P&gt;We saw this problem with a customer deployment as well.&amp;nbsp; It turned out that a different admin, not the main admin who was usually on the box, had set Splunkd some time ago to only be run as a certain domain user rather than as system.&lt;BR /&gt;&lt;BR /&gt;The msi's upgrade at the end restarts splunk but I guess it ends up restarting as the user who ran the msi, so it fails.&amp;nbsp;&amp;nbsp;&amp;nbsp; Another clue was that restarting splunkd on the command line,&amp;nbsp; by the administrator user,&amp;nbsp; failed with "splunk stopped" as the only output.&lt;/P&gt;&lt;P&gt;tacking launchsplunk=0 onto the msi invocation was the answer ultimately.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;and then the admins set Splunk back to just run as System so it wouldn't cause any unexpected problems going forward&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 20:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/744517#M14357</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2025-04-18T20:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk upgrade to version 9.1.0.1 end prematurely?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/750830#M14412</link>
      <description>&lt;P&gt;I don't see where you address your the issue of the service not starting after you complete the install "&lt;SPAN&gt;Alright, that may get it installed, but afterwards you will notice it does not want to start, but that's ok, I will show you what to do to get it to start in the follow up post."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2025 17:41:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/750830#M14412</guid>
      <dc:creator>BelCySecConsult</dc:creator>
      <dc:date>2025-07-31T17:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk upgrade to version 9.1.0.1 end prematurely?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/750910#M14415</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/270102"&gt;@MKhan1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Using LAUNCHSPLUNK=0 just ignores any problem during Splunk starting up, so unfortunately it still could be pretty much anything.&amp;nbsp; If you run splunk start from a command line, what does it say?&amp;nbsp; Have you tried checking EventLogs and splunkd.log?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 09:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-upgrade-to-version-9-1-0-1-end-prematurely/m-p/750910#M14415</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2025-08-01T09:56:58Z</dc:date>
    </item>
  </channel>
</rss>

