Getting Data In

How to uninstall/reinstall Universal Forwarder

ericlew
New Member

I have uninstalled the collector (ver. splunkforwarder-6.3.0-aa7d4b1ccb80-x64-release.msi) on Server 2012 R2, when I try to reinstall it I get the message "Product: UniversalForwarder -- This version of UniversalForwarder has already been installed on this computer." I uninstalled using add/remove programs, have rebooted, checked the registry for anything Splunk related and cant find anything.

any suggestions ?

Thanks, Eric

0 Karma

splunkcol
Builder


1. enter CMD as administrator
2. write the WMIC command
3. type the PRODUCT GET NAME command
4. you will see a list of all the programs installed in the operating system where the name of the Universal forwarder is "UniversalForwarder"
5. If you want to see general information about the program, you can execute the command PRODUCT WHERE NAME = "UniversalForwarder"
6. Now to uninstall the Universal forwarder use the command PRODUCT WHERE NAME = "UniversalForwarder" call uninstall (when a message appears press Y to confirm the uninstallation)

this video helped me
https://www.youtube.com/watch?v=dX2usQvNUeM

0 Karma

bschwind
Engager

I received same error. Version: splunkforwarder-6.3.0-aa7d4b1ccb80-x64-release.msi.
The right-click and uninstall did not work for me.

I fixed it and was able to install by deleting the following registry key. HKEY_CLASSES_ROOT\Installer\Products\C042F9A1CE44AA641A538C56CC9204B1

vasanthmss
Motivator

Have you check the services?

V
0 Karma

ericlew
New Member

Yes, the uninstall removed the directory, however, I think I just fixed the issue. I right clicked on the splunkforwarder-6.3.0-aa7d4b1ccb80-x64-release.msi file and there was an option to Uninstall, which I selected, it looked like it actually was doing something, and I can now run through the install

thank you for your reply

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you deleted the Splunk directory? It may be called "Splunk Universal Forwarder".

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...