Deployment Architecture

Splunk Universal Forwarder 7.x setup ended prematurely on Windows Server 2012 R2 Datacenter edition

kutlusensoy
New Member

Hi everyone,

I've read lots of articles for that issue, but I can't find any solutions.

Here is the premature splunk-utility.log content

2-13-2019 11:56:48.198 +0300 INFO  ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
02-13-2019 11:56:48.198 +0300 INFO  ServerConfig - Host name option is "".
02-13-2019 11:56:49.983 +0300 INFO  loader - Running utility: "check-transforms-keys"
02-13-2019 11:56:49.983 +0300 INFO  loader - Getting configuration data from: c:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml
02-13-2019 11:56:49.983 +0300 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to c:\Program Files\SplunkUniversalForwarder\etc\modules
02-13-2019 11:56:49.983 +0300 INFO  loader - loading modules from c:\Program Files\SplunkUniversalForwarder\etc\modules
02-13-2019 11:56:49.999 +0300 INFO  loader - Writing out composite configuration file: c:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml

And also, I can read that Setup Failed because of Error code 1603 from log files in C:\TMP

Do you have any suggestion to solve this problem.

Thanks.

0 Karma

ddrillic
Ultra Champion

How does the splunkd.log end?

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...