windows could not start splunkforwarder service on local computer
error - 1067 - The process terminated unexpectedly
splunkd logs , Where do I look for lock files , How to solve this on windows
10-12-2019 09:59:33.615 -0700 FATAL loader - Timed out waiting for config lock; see splunkd_stderr.log for details. Exiting.
10-12-2019 10:00:34.568 -0700 WARN loader - Sleep 10 sec, waiting for config lock.
10-12-2019 10:00:44.584 -0700 WARN loader - Sleep 10 sec, waiting for config lock.
10-12-2019 10:00:54.600 -0700 WARN loader - Sleep 10 sec, waiting for config lock.
10-12-2019 10:01:04.615 -0700 WARN loader - Sleep 10 sec, waiting for config lock.
10-12-2019 10:01:14.631 -0700 WARN loader - Sleep 10 sec, waiting for config lock.
10-12-2019 10:01:24.647 -0700 WARN loader - Sleep 10 sec, waiting for config lock.
10-12-2019 10:01:34.662 -0700 FATAL loader - Timed out waiting for config lock; see splunkd_stderr.log for details. Exiting.
10-12-2019 10:01:51.147 -0700 WARN loader - Sleep 10 sec, waiting for config lock.
10-12-2019 10:02:01.163 -0700 WARN loader - Sleep 10 sec, waiting for config lock.
As mentioned on the previously post by richgalloway, you have to check the error messages on file splunkd_stderr.log.
Check if the user that you are installing the UF client has the access granted to start the service
you can either use the windows system local account or domain account where the user has privilege access to start splunk service
Remove the UF client from this server.
Verify if you have any local server police from anti-virus or other software that monitores the server that can prevent splunk service to be started.
Also check the windows logs on the server, because if there is any problem with permissions, there is potential the error will be there
Install the UF client again on a sandbox server where you can run your troubleshooting or either test the different windows accounts who has access to process changes on the system.
What does it say in splunkd_stderr.log?
Hey,
I don't have this log file under C:\Program Files\SplunkUniversalForwarder\var\log\splunk