<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Install issue on Server 2016 in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540161#M7186</link>
    <description>&lt;P&gt;&amp;nbsp;Had Splunk Enterprise 7 running and recently updated to 8.1.2. After going over the fundamentals video I wanted to install using customize and Active directory on my Server 2016 Active Directory server. So I removed Splunk and tried to reinstall using the customize. It get most of the way done and then it does a rollback.&amp;nbsp; Looked in C:\Program files\Splunk for logs and found Splunkd-utility&lt;/P&gt;&lt;P&gt;02-16-2021 14:49:56.946 -0500 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml&lt;BR /&gt;02-16-2021 14:49:56.947 -0500 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules&lt;BR /&gt;02-16-2021 14:49:56.947 -0500 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules&lt;BR /&gt;02-16-2021 14:49:56.951 -0500 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml&lt;BR /&gt;02-16-2021 14:49:56.972 -0500 WARN Pstacks - Backtracing is not initialized - GeneratePstacksAction cannot be used..&lt;BR /&gt;02-16-2021 14:49:56.972 -0500 WARN WatchdogActions - Initialization failed for action=pstacks. Deleting.&lt;BR /&gt;02-16-2021 14:49:56.972 -0500 INFO loader - Service "Splunkd" does not exist&lt;BR /&gt;02-16-2021 14:49:56.972 -0500 INFO loader - Skipping validation of index paths because may not be running as the correct user&lt;BR /&gt;02-16-2021 14:49:56.972 -0500 INFO loader - Validated 10 indexes in 0 microseconds&lt;BR /&gt;02-16-2021 14:49:57.235 -0500 INFO ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.&lt;BR /&gt;02-16-2021 14:49:57.235 -0500 INFO ServerConfig - Host name option is "".&lt;BR /&gt;02-16-2021 14:49:58.337 -0500 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml&lt;BR /&gt;02-16-2021 14:49:58.337 -0500 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules&lt;BR /&gt;02-16-2021 14:49:58.337 -0500 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules&lt;BR /&gt;02-16-2021 14:49:58.337 -0500 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Feb 2021 20:21:19 GMT</pubDate>
    <dc:creator>dflatley</dc:creator>
    <dc:date>2021-02-16T20:21:19Z</dc:date>
    <item>
      <title>Install issue on Server 2016</title>
      <link>https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540161#M7186</link>
      <description>&lt;P&gt;&amp;nbsp;Had Splunk Enterprise 7 running and recently updated to 8.1.2. After going over the fundamentals video I wanted to install using customize and Active directory on my Server 2016 Active Directory server. So I removed Splunk and tried to reinstall using the customize. It get most of the way done and then it does a rollback.&amp;nbsp; Looked in C:\Program files\Splunk for logs and found Splunkd-utility&lt;/P&gt;&lt;P&gt;02-16-2021 14:49:56.946 -0500 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml&lt;BR /&gt;02-16-2021 14:49:56.947 -0500 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules&lt;BR /&gt;02-16-2021 14:49:56.947 -0500 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules&lt;BR /&gt;02-16-2021 14:49:56.951 -0500 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml&lt;BR /&gt;02-16-2021 14:49:56.972 -0500 WARN Pstacks - Backtracing is not initialized - GeneratePstacksAction cannot be used..&lt;BR /&gt;02-16-2021 14:49:56.972 -0500 WARN WatchdogActions - Initialization failed for action=pstacks. Deleting.&lt;BR /&gt;02-16-2021 14:49:56.972 -0500 INFO loader - Service "Splunkd" does not exist&lt;BR /&gt;02-16-2021 14:49:56.972 -0500 INFO loader - Skipping validation of index paths because may not be running as the correct user&lt;BR /&gt;02-16-2021 14:49:56.972 -0500 INFO loader - Validated 10 indexes in 0 microseconds&lt;BR /&gt;02-16-2021 14:49:57.235 -0500 INFO ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.&lt;BR /&gt;02-16-2021 14:49:57.235 -0500 INFO ServerConfig - Host name option is "".&lt;BR /&gt;02-16-2021 14:49:58.337 -0500 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml&lt;BR /&gt;02-16-2021 14:49:58.337 -0500 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules&lt;BR /&gt;02-16-2021 14:49:58.337 -0500 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules&lt;BR /&gt;02-16-2021 14:49:58.337 -0500 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 20:21:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540161#M7186</guid>
      <dc:creator>dflatley</dc:creator>
      <dc:date>2021-02-16T20:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Install issue on Server 2016</title>
      <link>https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540173#M7187</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231578"&gt;@dflatley&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;To troubleshoot further we'll need logs from &lt;FONT face="courier new,courier"&gt;msiexec.exe&lt;/FONT&gt;.&amp;nbsp; You can generate them by doing something like the following from a command prompt:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;msiexec /l*vx msiexec.log /i &amp;lt;splunk.msi&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;(Where &lt;FONT face="courier new,courier"&gt;&amp;lt;splunk.msi&amp;gt;&lt;/FONT&gt; is replaced with the filename of the MSI.)&lt;/P&gt;&lt;P&gt;If you then search &lt;FONT face="courier new,courier"&gt;msiexec.log&lt;/FONT&gt; for the string &lt;STRONG&gt;&lt;EM&gt;return value 3&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt; and paste 20 or so lines immediately preceding it, hopefully that will tell us what has gone wrong.&lt;/P&gt;&lt;P&gt;There may also be a file in &lt;FONT face="courier new,courier"&gt;%TEMP%&lt;/FONT&gt; called &lt;FONT face="courier new,courier"&gt;splunk.log&lt;/FONT&gt;.&amp;nbsp; That may also help shed some light.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Jo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 23:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Install-issue-on-Server-2016/m-p/540173#M7187</guid>
      <dc:creator>jho-splunk</dc:creator>
      <dc:date>2021-02-16T23:02:45Z</dc:date>
    </item>
  </channel>
</rss>

