<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder Problem in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445618#M8680</link>
    <description>&lt;P&gt;This is a Snippet:&lt;/P&gt;

&lt;P&gt;9:20:54 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/outputs/tcp/server "name=165.112.254.26:9997" &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
HTTP/1.1 400 Bad Request&lt;BR /&gt;
Date: Wed, 20 Mar 2019 13:20:54 GMT&lt;BR /&gt;
Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;
Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;
Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;
X-Content-Type-Options: nosniff&lt;BR /&gt;
Content-Length: 170&lt;BR /&gt;
Connection: Close&lt;BR /&gt;
X-Frame-Options: SAMEORIGIN&lt;BR /&gt;
Server: Splunkd&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;msg type="ERROR"&amp;gt;165.112.254.26:9997 forwarded-server already present&amp;lt;/msg&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DS init failed: Deployment Server not available on a dedicated forwarder.&lt;BR /&gt;
9:20:54 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd uninstall &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
Removing service SplunkForwarder&lt;BR /&gt;
Service removed&lt;BR /&gt;
Disabled.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2019 14:33:13 GMT</pubDate>
    <dc:creator>carbin</dc:creator>
    <dc:date>2019-03-20T14:33:13Z</dc:date>
    <item>
      <title>Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445616#M8678</link>
      <description>&lt;P&gt;Here is my situation, we had a test installation of Splunk Enterprise 7.2.4 on Server1, with Universal Forwarders installed on Server2 &amp;amp; Server3, just generic Windows Servers. Events were arriving in Splunk Enterprise, and all was good until our license expired. &lt;/P&gt;

&lt;P&gt;We then received a Developer License so that my Federal Agency can test it.&lt;/P&gt;

&lt;P&gt;I uninstalled the Universal Forwarder via Add/Remove Programs &amp;amp; rebooted.&lt;/P&gt;

&lt;P&gt;Then since 7.2.5 was released I downloaded that and installed Splunk Enterprise on new Server4 and installed the Universal Forwarders (7.2.5) on Server2 &amp;amp; Server3.&lt;/P&gt;

&lt;P&gt;I am not getting events into Splunk Enterprise, so I thought I would uninstall &amp;amp; reinstall the Universal Forwarder on Server2 &amp;amp; Server3 again. &lt;/P&gt;

&lt;P&gt;It will not install, the old Universal Forwarder folders and files still exist, but I cannot either Install, Repair, or Uninstall now.&lt;/P&gt;

&lt;P&gt;What do I do to remove the old UF installation and reinstall? &lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 13:41:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445616#M8678</guid>
      <dc:creator>carbin</dc:creator>
      <dc:date>2019-03-20T13:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445617#M8679</link>
      <description>&lt;P&gt;Have you looked in the %TEMP%/splunkInstall.log file - If the install is failing it should contain details on the reason why.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 14:27:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445617#M8679</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-20T14:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445618#M8680</link>
      <description>&lt;P&gt;This is a Snippet:&lt;/P&gt;

&lt;P&gt;9:20:54 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/outputs/tcp/server "name=165.112.254.26:9997" &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
HTTP/1.1 400 Bad Request&lt;BR /&gt;
Date: Wed, 20 Mar 2019 13:20:54 GMT&lt;BR /&gt;
Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;
Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;
Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;
X-Content-Type-Options: nosniff&lt;BR /&gt;
Content-Length: 170&lt;BR /&gt;
Connection: Close&lt;BR /&gt;
X-Frame-Options: SAMEORIGIN&lt;BR /&gt;
Server: Splunkd&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;msg type="ERROR"&amp;gt;165.112.254.26:9997 forwarded-server already present&amp;lt;/msg&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DS init failed: Deployment Server not available on a dedicated forwarder.&lt;BR /&gt;
9:20:54 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd uninstall &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
Removing service SplunkForwarder&lt;BR /&gt;
Service removed&lt;BR /&gt;
Disabled.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 14:33:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445618#M8680</guid>
      <dc:creator>carbin</dc:creator>
      <dc:date>2019-03-20T14:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445619#M8681</link>
      <description>&lt;P&gt;The last 3 lines:&lt;/P&gt;

&lt;P&gt;Removing service SplunkForwarder&lt;BR /&gt;
Service removed&lt;BR /&gt;
Disabled.&lt;/P&gt;

&lt;P&gt;Suggest that the uninstall completed. What is written to that log file if you reinstall again?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 14:55:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445619#M8681</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-20T14:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445620#M8682</link>
      <description>&lt;P&gt;cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /services/apps/local/SplunkUniversalForwarder/enable &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
HTTP/1.1 200 OK&lt;BR /&gt;
Date: Wed, 20 Mar 2019 13:20:54 GMT&lt;BR /&gt;
Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;
Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;
Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;
X-Content-Type-Options: nosniff&lt;BR /&gt;
Content-Length: 1930&lt;BR /&gt;
Connection: Close&lt;BR /&gt;
X-Frame-Options: SAMEORIGIN&lt;BR /&gt;
Server: Splunkd&lt;/P&gt;

&lt;P&gt;/services/apps/local&lt;BR /&gt;
  2019-03-20T09:20:54-04:00&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;name&amp;gt;Splunk&amp;lt;/name&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;0&lt;BR /&gt;
  30&lt;BR /&gt;
  0&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;s:msg type="INFO"&amp;gt;Restart required by: default-mode, limits, server, web&amp;lt;/s:msg&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DS init failed: Deployment Server not available on a dedicated forwarder.&lt;BR /&gt;
9:20:54 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/outputs/tcp/server "name=165.112.254.26:9997" &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
HTTP/1.1 400 Bad Request&lt;BR /&gt;
Date: Wed, 20 Mar 2019 13:20:54 GMT&lt;BR /&gt;
Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;
Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;
Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;
X-Content-Type-Options: nosniff&lt;BR /&gt;
Content-Length: 170&lt;BR /&gt;
Connection: Close&lt;BR /&gt;
X-Frame-Options: SAMEORIGIN&lt;BR /&gt;
Server: Splunkd&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;msg type="ERROR"&amp;gt;165.112.254.26:9997 forwarded-server already present&amp;lt;/msg&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DS init failed: Deployment Server not available on a dedicated forwarder.&lt;BR /&gt;
9:20:54 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd uninstall &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
Removing service SplunkForwarder&lt;BR /&gt;
Service removed&lt;BR /&gt;
Disabled.&lt;BR /&gt;
11:12:37 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal first-time-run --answer-yes --no-prompt &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;/P&gt;

&lt;P&gt;This appears to be an upgrade of Splunk.&lt;BR /&gt;
--------------------------------------------------------------------------------)&lt;/P&gt;

&lt;P&gt;Splunk has detected an older version of Splunk installed on this machine. To&lt;BR /&gt;
finish upgrading to the new version, Splunk's installer will automatically&lt;BR /&gt;
update and alter your current configuration files. Deprecated configuration&lt;BR /&gt;
files will be renamed with a .deprecated extension.&lt;/P&gt;

&lt;P&gt;You can choose to preview the changes that will be made to your configuration&lt;BR /&gt;
files before proceeding with the migration and upgrade:&lt;/P&gt;

&lt;P&gt;If you want to migrate and upgrade without previewing the changes that will be&lt;BR /&gt;
made to your existing configuration files, choose 'y'.&lt;BR /&gt;
If you want to see what changes will be made before you proceed with the&lt;BR /&gt;
upgrade, choose 'n'.&lt;/P&gt;

&lt;P&gt;Perform migration and upgrade without previewing configuration changes? [y/n] y&lt;/P&gt;

&lt;P&gt;Migrating to:&lt;BR /&gt;
VERSION=7.2.5&lt;BR /&gt;
BUILD=088f49762779&lt;BR /&gt;
PRODUCT=splunk&lt;BR /&gt;
PLATFORM=Windows-AMD64&lt;/P&gt;

&lt;P&gt;It seems that the Splunk default certificates are being used. If certificate validation is turned on using the default certificates (not-recommended), this may result in loss of communication in mixed-version Splunk environments after upgrade.&lt;/P&gt;

&lt;P&gt;"N:\Program Files\SplunkUniversalForwarder\etc\auth\ca.pem": already a renewed Splunk certificate: skipping renewal&lt;BR /&gt;
"N:\Program Files\SplunkUniversalForwarder\etc\auth\cacert.pem": already a renewed Splunk certificate: skipping renewal&lt;BR /&gt;
[App Key Value Store migration] Binary for service(34) is missing.&lt;BR /&gt;
[App Key Value Store migration] Binary for service(34) is missing.&lt;/P&gt;

&lt;P&gt;-- Migration information is being logged to 'N:\Program Files\SplunkUniversalForwarder\var\log\splunk\migration.log.2019-03-20.11-12-38' --&lt;BR /&gt;
11:12:41 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
    Checking conf files for problems...&lt;BR /&gt;
    Done&lt;BR /&gt;
    Checking default conf files for edits...&lt;BR /&gt;
    Validating installed files against hashes from 'N:\Program Files\SplunkUniversalForwarder\splunkforwarder-7.2.5-088f49762779-windows-64-manifest'&lt;BR /&gt;
    All installed files intact.&lt;BR /&gt;
    Done&lt;BR /&gt;
11:12:45 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd install --startup=auto &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
Installing service SplunkForwarder&lt;BR /&gt;
Service installed&lt;BR /&gt;
11:12:46 AM&lt;BR /&gt;
cmd.exe /c "icacls "N:\Program Files\SplunkUniversalForwarder\etc" /T /C /grant *S-1-5-32-544:f &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\copyright.txt&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\datetime.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\deployment-apps&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\disabled-apps&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\licenses&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\log-btool-debug.cfg&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\log-btool.cfg&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\log-cmdline-debug.cfg&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\log-cmdline.cfg&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\log-debug.cfg&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\log-utility.cfg&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\log.cfg&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\myinstall&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\passwd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\prettyprint.xsl&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\shcluster&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\splunk-launch.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\splunk-launch.conf.default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\splunk.version&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\users&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\learned&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\search&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\splunk_httpinput&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\bin&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\bin\collector.path&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\default\app.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\default\inputs.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\default\README&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\default\server.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\learned\default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\learned\metadata&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\learned\default\README&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\learned\metadata\default.meta&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\search\default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\search\metadata&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\search\default\app.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\search\default\inputs.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\search\default\props.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\search\default\restmap.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\search\default\transforms.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\search\metadata\default.meta&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\metadata&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\app.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\default-mode.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\inputs.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\limits.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\outputs.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\props.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\README&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\server.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\web.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\app.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\metadata\default.meta&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\metadata\local.meta&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\splunk_httpinput\default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\apps\splunk_httpinput\default\inputs.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth.rnd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\appsCA.pem&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\appsLicenseCA.pem&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\ca.pem&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\ca.pem.default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\ca.srl&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\cacert.pem&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\cacert.pem.default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\cloudCA.pem&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\crl&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\prev_release&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\server.pem&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\splunk.secret&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\crl\README&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\prev_release\ca.pem.default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\auth\prev_release\cacert.pem.default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\deployment-apps\README&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\disabled-apps\README&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\licenses\forwarder&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\licenses\forwarder\splunkforwarder.lic&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\parsing&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\exec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\fschangemanager&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\RemoteQueue&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\structuredparsing&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\tailfile&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\TCP&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\UDP&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\wineventlog&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\winparsing&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\exec\config.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\fschangemanager\config.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\RemoteQueue\config.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\structuredparsing\config.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\tailfile\config.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\TCP\config.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\UDP\config.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\wineventlog\config.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\input\winparsing\config.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\modules\parsing\config.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml.cfg-default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\shcluster\apps&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\shcluster\users&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\shcluster\apps\README&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\shcluster\users\README&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\local&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\metadata&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\static&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin\admon.cmd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin\MonitorNoHandle.cmd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin\perfmon.cmd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin\powershell.cmd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin\powershell2.cmd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin\winEventLog.cmd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin\WinHostMon.cmd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin\WinNetMon.cmd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin\WinPrintMon.cmd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\bin\WinRegMon.cmd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\alert_actions.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\app.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\audit.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\authentication.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\authorize.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\conf.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\default-mode.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\health.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\inputs.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\limits.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\literals.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\livetail.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\messages.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\outputs.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\procmon-filters.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\props.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\restmap.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\server.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\source-classifier.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\sourcetypes.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\telemetry.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\visualizations.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\web.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\workload_pools.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\default\workload_rules.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\local\authentication.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\local\migration.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\local\outputs.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\local\README&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\local\server.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\local\user-seed.conf&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\metadata\default.meta&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\metadata\local.meta&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\alert_actions.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\alert_actions.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\audit.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\audit.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\authentication.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\authentication.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\authorize.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\authorize.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\checklist.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\collections.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\collections.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\conf_checker.rules&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\default-mode.conf.examples&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\default-mode.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\default.meta.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\default.meta.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\deploymentclient.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\deploymentclient.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\health.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\health.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\inputs.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\inputs.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\instance.cfg.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\instance.cfg.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\limits.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\limits.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\literals.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\literals.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\livetail.conf.examples&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\livetail.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\messages.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\messages.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\migration.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\outputs.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\outputs.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\passwords.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\passwords.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\procmon-filters.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\procmon-filters.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\props.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\props.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\restmap.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\restmap.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\server.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\server.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\serverclass.seed.xml.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\source-classifier.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\source-classifier.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\sourcetypes.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\sourcetypes.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\splunk-launch.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\user-prefs.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\user-prefs.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\user-seed.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\user-seed.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\visualizations.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\web.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\web.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\wmi.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\wmi.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\workload_pools.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\workload_pools.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\workload_rules.conf.example&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\README\workload_rules.conf.spec&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\static\atom.xsl&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\system\static\splunkrc_cmds.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\etc\users\users.ini&lt;BR /&gt;
Successfully processed 230 files; Failed processing 0 files&lt;BR /&gt;
11:12:46 AM&lt;BR /&gt;
cmd.exe /c "icacls "N:\Program Files\SplunkUniversalForwarder\var" /T /C /grant *S-1-5-32-544:f &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\lib&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\log&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\spool&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\lib\splunk&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\lib\splunk\authDb&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\lib\splunk\fishbucket&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\lib\splunk\hashDb&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\lib\splunk\persistentstorage&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\lib\splunk\fishbucket\rawdata&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\lib\splunk\persistentstorage\audit&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\log\introspection&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\log\splunk&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\log\watchdog&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\log\splunk\btool.log&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\log\splunk\first_install.log&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\log\splunk\migration.log.2019-03-20.09-01-52&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\log\splunk\migration.log.2019-03-20.09-20-44&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\log\splunk\migration.log.2019-03-20.11-12-38&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd-utility.log&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run.rnd&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run\splunk&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run\splunk\cachemanager_upload.json&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run\splunk\upload&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\i18n&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\modules&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\modules\static&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\modules\static\css&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\spool\dirmoncache&lt;BR /&gt;
processed file: N:\Program Files\SplunkUniversalForwarder\var\spool\splunk&lt;BR /&gt;
Successfully processed 35 files; Failed processing 0 files&lt;BR /&gt;
11:12:46 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /services/apps/local/SplunkUniversalForwarder/enable &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
HTTP/1.1 200 OK&lt;BR /&gt;
Date: Wed, 20 Mar 2019 15:12:48 GMT&lt;BR /&gt;
Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;
Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;
Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;
X-Content-Type-Options: nosniff&lt;BR /&gt;
Content-Length: 1930&lt;BR /&gt;
Connection: Close&lt;BR /&gt;
X-Frame-Options: SAMEORIGIN&lt;BR /&gt;
Server: Splunkd&lt;/P&gt;

&lt;P&gt;/services/apps/local&lt;BR /&gt;
  2019-03-20T11:12:48-04:00&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;name&amp;gt;Splunk&amp;lt;/name&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;0&lt;BR /&gt;
  30&lt;BR /&gt;
  0&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;s:msg type="INFO"&amp;gt;Restart required by: default-mode, limits, server, web&amp;lt;/s:msg&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DS init failed: Deployment Server not available on a dedicated forwarder.&lt;BR /&gt;
11:12:48 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/outputs/tcp/server "name=165.112.254.26:9997" &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
HTTP/1.1 400 Bad Request&lt;BR /&gt;
Date: Wed, 20 Mar 2019 15:12:48 GMT&lt;BR /&gt;
Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;
Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;
Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;
X-Content-Type-Options: nosniff&lt;BR /&gt;
Content-Length: 170&lt;BR /&gt;
Connection: Close&lt;BR /&gt;
X-Frame-Options: SAMEORIGIN&lt;BR /&gt;
Server: Splunkd&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;msg type="ERROR"&amp;gt;165.112.254.26:9997 forwarded-server already present&amp;lt;/msg&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DS init failed: Deployment Server not available on a dedicated forwarder.&lt;BR /&gt;
11:12:48 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd uninstall &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
Removing service SplunkForwarder&lt;BR /&gt;
Service removed&lt;BR /&gt;
Disabled.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:46:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445620#M8682</guid>
      <dc:creator>carbin</dc:creator>
      <dc:date>2020-09-29T23:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445621#M8683</link>
      <description>&lt;P&gt;If you go to add-remove programs is the Splunk UF now gone?&lt;BR /&gt;
If not, remove it from add/remove etc&lt;BR /&gt;
Then move the folder from program files, and reinstall again. &lt;BR /&gt;
It seems maybe the old installation directory is causing some odd behavior.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 15:50:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445621#M8683</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-20T15:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445622#M8684</link>
      <description>&lt;P&gt;So, I moved the entire SplunkUniversalForwarder folder from Program Files to a temp folder and tried again:&lt;/P&gt;

&lt;P&gt;…&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /services/apps/local/SplunkUniversalForwarder/enable &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
HTTP/1.1 200 OK&lt;BR /&gt;
Date: Wed, 20 Mar 2019 15:56:25 GMT&lt;BR /&gt;
Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;
Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;
Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;
X-Content-Type-Options: nosniff&lt;BR /&gt;
Content-Length: 1930&lt;BR /&gt;
Connection: Close&lt;BR /&gt;
X-Frame-Options: SAMEORIGIN&lt;BR /&gt;
Server: Splunkd&lt;/P&gt;

&lt;P&gt;/services/apps/local&lt;BR /&gt;
  2019-03-20T11:56:25-04:00&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;name&amp;gt;Splunk&amp;lt;/name&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;0&lt;BR /&gt;
  30&lt;BR /&gt;
  0&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;s:msg type="INFO"&amp;gt;Restart required by: default-mode, limits, server, web&amp;lt;/s:msg&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DS init failed: Deployment Server not available on a dedicated forwarder.&lt;BR /&gt;
11:56:25 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd rest --noauth POST /servicesNS/nobody/SplunkUniversalForwarder/data/outputs/tcp/server "name=165.112.254.26:9997" &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
HTTP/1.1 201 Created&lt;BR /&gt;
Date: Wed, 20 Mar 2019 15:56:25 GMT&lt;BR /&gt;
Expires: Thu, 26 Oct 1978 00:00:00 GMT&lt;BR /&gt;
Cache-Control: no-store, no-cache, must-revalidate, max-age=0&lt;BR /&gt;
Content-Type: text/xml; charset=UTF-8&lt;BR /&gt;
X-Content-Type-Options: nosniff&lt;BR /&gt;
Content-Length: 4439&lt;BR /&gt;
Connection: Close&lt;BR /&gt;
X-Frame-Options: SAMEORIGIN&lt;BR /&gt;
Server: Splunkd&lt;/P&gt;

&lt;P&gt;/servicesNS/nobody/SplunkUniversalForwarder/data/outputs/tcp/server&lt;BR /&gt;
  2019-03-20T11:56:25-04:00&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;name&amp;gt;Splunk&amp;lt;/name&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;1&lt;BR /&gt;
  30&lt;BR /&gt;
  0&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;title&amp;gt;165.112.254.26:9997&amp;lt;/title&amp;gt;
&amp;lt;id&amp;gt;/servicesNS/nobody/system/data/outputs/tcp/server/165.112.254.26%3A9997&amp;lt;/id&amp;gt;
&amp;lt;updated&amp;gt;1969-12-31T19:00:00-05:00&amp;lt;/updated&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/outputs/tcp/server/165.112.254.26%3A9997" rel="alternate"/&amp;gt;
&amp;lt;author&amp;gt;
  &amp;lt;name&amp;gt;nobody&amp;lt;/name&amp;gt;
&amp;lt;/author&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/outputs/tcp/server/165.112.254.26%3A9997" rel="list"/&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/outputs/tcp/server/165.112.254.26%3A9997/_reload" rel="_reload"/&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/outputs/tcp/server/165.112.254.26%3A9997" rel="edit"/&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/outputs/tcp/server/165.112.254.26%3A9997" rel="remove"/&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/outputs/tcp/server/165.112.254.26%3A9997/allconnections" rel="allconnections"/&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/outputs/tcp/server/165.112.254.26%3A9997/disable" rel="disable"/&amp;gt;
&amp;lt;content type="text/xml"&amp;gt;
  &amp;lt;s:dict&amp;gt;
    &amp;lt;s:key name="destHost"&amp;gt;165.112.254.26&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="destIp"&amp;gt;165.112.254.26&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="destPort"&amp;gt;9997&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="eai:acl"&amp;gt;
      &amp;lt;s:dict&amp;gt;
        &amp;lt;s:key name="app"&amp;gt;system&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="can_change_perms"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="can_list"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="can_share_app"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="can_share_global"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="can_share_user"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="can_write"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="modifiable"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="owner"&amp;gt;nobody&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="perms"&amp;gt;
          &amp;lt;s:dict&amp;gt;
            &amp;lt;s:key name="read"&amp;gt;
              &amp;lt;s:list&amp;gt;
                &amp;lt;s:item&amp;gt;*&amp;lt;/s:item&amp;gt;
              &amp;lt;/s:list&amp;gt;
            &amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="write"&amp;gt;
              &amp;lt;s:list&amp;gt;
                &amp;lt;s:item&amp;gt;*&amp;lt;/s:item&amp;gt;
              &amp;lt;/s:list&amp;gt;
            &amp;lt;/s:key&amp;gt;
          &amp;lt;/s:dict&amp;gt;
        &amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="removable"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="sharing"&amp;gt;system&amp;lt;/s:key&amp;gt;
      &amp;lt;/s:dict&amp;gt;
    &amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="method"&amp;gt;autobalance&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="sourcePort"&amp;gt;8089&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="status"&amp;gt;not_connected&amp;lt;/s:key&amp;gt;
  &amp;lt;/s:dict&amp;gt;
&amp;lt;/content&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DS init failed: Deployment Server not available on a dedicated forwarder.&lt;BR /&gt;
11:56:26 AM&lt;BR /&gt;
cmd.exe /c ""N:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" cmd splunkd uninstall &amp;gt;&amp;gt; "C:\Users\NINDSS~1\AppData\Local\Temp\splunk.log" 2&amp;gt;&amp;amp;1"&lt;BR /&gt;
Removing service SplunkForwarder&lt;BR /&gt;
Service removed&lt;BR /&gt;
Disabled.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 15:58:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445622#M8684</guid>
      <dc:creator>carbin</dc:creator>
      <dc:date>2019-03-20T15:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445623#M8685</link>
      <description>&lt;P&gt;Is 165.112.254.26 the IP of the old server, or the new one?&lt;/P&gt;

&lt;P&gt;I had been assuming that it was the old server?&lt;/P&gt;

&lt;P&gt;If you run a search on your new Splunk server for:&lt;BR /&gt;
&lt;CODE&gt;index=_internal |stats count by host&lt;/CODE&gt;&lt;BR /&gt;
Do you see your forwarders in the results?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 16:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445623#M8685</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-20T16:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445624#M8686</link>
      <description>&lt;P&gt;That is the IP of the new server. When I run that search, it only returns one Host, the Splunk Ent server. I'm thinking Registry Keys must be holding me up&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 16:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445624#M8686</guid>
      <dc:creator>carbin</dc:creator>
      <dc:date>2019-03-20T16:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445625#M8687</link>
      <description>&lt;P&gt;In desperation I went to my other test server and did the following:&lt;/P&gt;

&lt;P&gt;1: Verified that Add/Remove Programs did NOT contain Universal Forwarder&lt;BR /&gt;
2: Moved the original install folder to a new Temp folder&lt;BR /&gt;
3: Opened Regedit and searched for "splunk"&lt;BR /&gt;
4: Deleted all that matched&lt;BR /&gt;
5: Rebooted server&lt;BR /&gt;
6: Attempted Installation. It failed and rolled back.&lt;/P&gt;

&lt;P&gt;Did I miss Registry Keys?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 17:27:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445625#M8687</guid>
      <dc:creator>carbin</dc:creator>
      <dc:date>2019-03-20T17:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445626#M8688</link>
      <description>&lt;P&gt;In desperation I went to my other test server and did the following:&lt;/P&gt;

&lt;P&gt;1: Verified that Add/Remove Programs did NOT contain Universal Forwarder&lt;BR /&gt;
2: Moved the original install folder to a new Temp folder&lt;BR /&gt;
3: Opened Regedit and searched for "splunk"&lt;BR /&gt;
4: Deleted all that matched&lt;BR /&gt;
5: Rebooted server&lt;BR /&gt;
6: Attempted Installation. It failed and rolled back.&lt;/P&gt;

&lt;P&gt;Did I miss Registry Keys?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 17:27:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445626#M8688</guid>
      <dc:creator>carbin</dc:creator>
      <dc:date>2019-03-20T17:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445627#M8689</link>
      <description>&lt;P&gt;You can try this, which I found referenced in another post.&lt;BR /&gt;
It will forcefully remove a UF, but please read the warnings, and satisfy yourself that you are comfortable before executing it.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://github.com/dstaulcu/SplunkTools/blob/master/Remove-UniversalForwarder-BrokenMSI.ps1"&gt;https://github.com/dstaulcu/SplunkTools/blob/master/Remove-UniversalForwarder-BrokenMSI.ps1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 10:50:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445627#M8689</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-21T10:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Problem</title>
      <link>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445628#M8690</link>
      <description>&lt;P&gt;Thanks for the suggestion. I executed that PS script as admin, rebooted and still won't install. I may have to see if I can revert to an earlier snapshot of the VM (if one exists), but I'm unsure what I would do differently. Will the 7.2.5 installed upgrade or install over a 7.2.4 install?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 12:19:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Universal-Forwarder-Problem/m-p/445628#M8690</guid>
      <dc:creator>carbin</dc:creator>
      <dc:date>2019-03-21T12:19:38Z</dc:date>
    </item>
  </channel>
</rss>

