Getting Data In

Splunk remote upgrader Windows update issue

Solitus31
Explorer

Hello,

we are trying to use splunk_app_uf_remote_upgrade_windows to upgrade our UF using Deployment server.
I have installed version 1.0.2 and trying to update application to last packages 1.0.3

Actual state information (same for all servers):

  • All servers installed with same powershell script
  • Package installation directory is "C:\Program Files\splunkupgrader"
  • Service is correctly executed by "Local Admin"

Update process used:

  1. Add on DS packages 1.0.3 on local folder application
  2. Reload class to deploy it.

For unknown reason,  some UF failed to update remote upgrade application and  i found the following error log message on splunk_upgrader_upgrade.log : 
"ERROR Cannot find path 'C:\Windows\system32\2025-10-16-11-25-25' because it does not exist."

It's seems that where script "history.ps1" is executed, the $PSScriptRoot (defined on constants.ps1) is "C:\Windows\system32" instead of script directory ("C:\Program Files\splunkupgrader\bin").

Do you have some idea to solve this issue ?

I've tried to modify constants.ps1 on package 1.0.3 but (as expected) i have a signature check issue.

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Solitus31 

I have seen this issue with another customer and I think they had it confirmed via support that this was a bug but I cannot find the reference at the moment.

Are you able to try this with 10.0.5 and see if this resolve your issue? If not, I would recommend reaching out to Splunk Support at https://splunk.com/support with details of the issue and see if they can provide a workaround to bring you up to date. 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Solitus31
Explorer

Thanks for your reply.
I will investigate with Splunk support to understand why their is no issue when installation is done manually and why for unknown reason some server upgrade failed.
If something is found and issue solved, i will put information here too.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...