You can check the %temp% directory of the user that installed splunk and look for a MSIxxxxxxx.log file. If you have many of them -- look for the one that installed splunk.
If you cannot find it, you can explicitly create an install log file with the following cli command:
$ msiexec /i /l*v
The Microsoft MSI installer subsystem will create a log file there. Once created we can crack it open and look to see what is going on.
It's been a long time since I installed Splunk on Win2008R2 and I no longer have that system.
There are three places I can think of to look:
C:\, C:\Windows\Temp, and the Event Viewer.