Building for the Splunk Platform

Rollback during Installation Windows 64 bit

afez89
New Member

Hi Splunk,

I have trouble installing your software.
It goes into rollback stating an error detected but no mention of the error
I selected the Windows 64 bit version.

Please advice

Thanks and regardsalt text

Tags (1)
0 Karma

mlog
New Member

I have the same problem in the latest version. Can anyone help?

0 Karma

dkcampbell
New Member

I have the same issue, any new information about this when the user is already admin?,I'm having the same issue, any new information regarding this issue when you are an admin?

0 Karma

woodcock
Esteemed Legend

Every time that this has happened it has been a permissions problem. Either you are not an admin or you cannot write into Program Files to add Splunk. You can get more debug output like this:

https://answers.splunk.com/answers/1393/does-splunk-windows-installer-generates-any-logs-during-the-...

0 Karma

rajatban
New Member

I am facing the same issue, i am the admin of my system, tried to install multiple times but it rollsback,
Can some one guide me "or you cannot write Program Files to add Splunk" means and how can it be resolved
It rolls back at very last of the installation process, almost after 90-95% of completion

Log file details
11-19-2017 01:51:41.318 +0530 INFO loader - Running utility: "validatedb"
11-19-2017 01:51:41.490 +0530 INFO loader - Getting configuration data from: D:\etc\myinstall\splunkd.xml
11-19-2017 01:51:41.492 +0530 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to D:\etc\modules
11-19-2017 01:51:41.493 +0530 INFO loader - loading modules from D:\etc\modules
11-19-2017 01:51:41.603 +0530 INFO loader - Writing out composite configuration file: D:\var\run\splunk\composite.xml
11-19-2017 01:51:41.743 +0530 INFO loader - Validated 8 indexes in 94.00 milliseconds
11-19-2017 01:51:43.009 +0530 INFO ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
11-19-2017 01:51:43.010 +0530 INFO ServerConfig - Host name option is "".
11-19-2017 01:51:55.444 +0530 INFO loader - Running utility: "check-transforms-keys"
11-19-2017 01:51:55.451 +0530 INFO loader - Getting configuration data from: D:\etc\myinstall\splunkd.xml
11-19-2017 01:51:55.453 +0530 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to D:\etc\modules
11-19-2017 01:51:55.454 +0530 INFO loader - loading modules from D:\etc\modules
11-19-2017 01:51:55.494 +0530 INFO loader - Writing out composite configuration file: D:\var\run\splunk\composite.xml

0 Karma

nemri1
New Member

Hello, 

You should stop the splunk forwarder service.

then install the new agent by cmd line <msiexec.exe /i splunkuniversalforwarder.msi >

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...