<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Installation ended prematurely on fresh install of Splunk 7.3.3 on Windows Server 2016 index server. in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Installation-ended-prematurely-on-fresh-install-of-Splunk-7-3-3/m-p/519100#M6663</link>
    <description>&lt;P&gt;Fresh install of Splunk 7.3.3 on Windows Server 2016 index server.&lt;/P&gt;
&lt;P&gt;I kept getting the "Splunk installation ended prematurely" with no clear evidence as to why. I tried most of the possible solutions in older posts, with no improvement.&lt;/P&gt;
&lt;P&gt;Turns out my domain Splunk service account had been set up with membership in a slew of groups, including the domain admin group. This apparently caused a permissions disconnect in the index server local security policy, where both Deny logon as a batch job and Deny logon as a service included Domain Admin. So, even though my Splunk service account had permission to Logon as a batch job and Logon as a service, it was blocked because of the Domain Admin membership.&lt;/P&gt;
&lt;P&gt;I removed the service account from the Domain Admin group and the installation completed successfully.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Sep 2020 21:09:56 GMT</pubDate>
    <dc:creator>jeff47</dc:creator>
    <dc:date>2020-09-11T21:09:56Z</dc:date>
    <item>
      <title>Installation ended prematurely on fresh install of Splunk 7.3.3 on Windows Server 2016 index server.</title>
      <link>https://community.splunk.com/t5/Installation/Installation-ended-prematurely-on-fresh-install-of-Splunk-7-3-3/m-p/519100#M6663</link>
      <description>&lt;P&gt;Fresh install of Splunk 7.3.3 on Windows Server 2016 index server.&lt;/P&gt;
&lt;P&gt;I kept getting the "Splunk installation ended prematurely" with no clear evidence as to why. I tried most of the possible solutions in older posts, with no improvement.&lt;/P&gt;
&lt;P&gt;Turns out my domain Splunk service account had been set up with membership in a slew of groups, including the domain admin group. This apparently caused a permissions disconnect in the index server local security policy, where both Deny logon as a batch job and Deny logon as a service included Domain Admin. So, even though my Splunk service account had permission to Logon as a batch job and Logon as a service, it was blocked because of the Domain Admin membership.&lt;/P&gt;
&lt;P&gt;I removed the service account from the Domain Admin group and the installation completed successfully.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 21:09:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Installation-ended-prematurely-on-fresh-install-of-Splunk-7-3-3/m-p/519100#M6663</guid>
      <dc:creator>jeff47</dc:creator>
      <dc:date>2020-09-11T21:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunk installation ended prematurely</title>
      <link>https://community.splunk.com/t5/Installation/Installation-ended-prematurely-on-fresh-install-of-Splunk-7-3-3/m-p/519101#M6664</link>
      <description>&lt;P&gt;Can you check windows architecture and msi file architecture you downloaded from Splunk. Both should match.&lt;/P&gt;&lt;P&gt;if you are trying to install 32 bit splunk msi file on 64 bit windows server. Mostly you get that error.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 15:11:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Installation-ended-prematurely-on-fresh-install-of-Splunk-7-3-3/m-p/519101#M6664</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-11T15:11:58Z</dc:date>
    </item>
  </channel>
</rss>

