Getting Data In

Upgrading Splunk from 6.2. to 6.4 on Windows, why does it hang on "Please wait while the Setup Wizard installs Splunk Enterprise"?

skoelpin
SplunkTrust
SplunkTrust

I'm currently trying to upgrade from 6.2 to 6.4 on Windows and ran into an issue.

I ran the MSI file and most of the Splunk files have today's timestamp on it which indicates it was updated, but it's getting hung on the last step. There's no indication of an error, it's just frozen and says "Please wait while the Setup Wizard installs Splunk Enterprise". I restarted the server and tried again with the same results.

Has anyone else ran into this issue while upgrading?

Tags (3)
1 Solution

skoelpin
SplunkTrust
SplunkTrust

After speaking with Splunk support, this is a confirmed bug and has been kicked to Splunk dev

View solution in original post

skoelpin
SplunkTrust
SplunkTrust

After speaking with Splunk support, this is a confirmed bug and has been kicked to Splunk dev

DK_E
Explorer

I am experiencing the same problem.

After that I've tried to upgrade from 6.2 to 6.4 with no success. Alternatively I've upgraded Splunk from 6.2 to 6.3 and then tried from 6.3 to 6.4 with same results.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

@DK_E , can you click the "Me Too" button on the initial question?

I was finally able to get mine to upgrade. By any chance do you have an index with a ton of data in it? Do you have a summary index?

0 Karma

DK_E
Explorer

@skoelpin I did it once I've red the topic. Same for upvotes. 🙂
I didn't enable any summary indexes so far, I've checked 'Summary / Searches, reports, and alerts' and none has 'summary indexing' enabled.
We have in our environment 97 GB index and 41 GB index. Does this have an impact on the upgrade?

skoelpin
SplunkTrust
SplunkTrust

That's a pretty small environment so I doubt that would be the issue. We have a separate environment running Linux that is larger and the upgrade went pretty fast. Only on Windows did we have an issue.

Splunk support confirmed the bug when upgrading to 6.4 on a Windows 2012 R2 server.. I ultimately had to wait about 7 hours for the upgrade to finish

Also, if it rollsback during the upgrade you will most likely have to remove the version.txt file before starting the Splunk service back up.. If the version.txt file has v6.4 in it and you get rolled back to v6.2 then the Splunk service will not start until this file is removed

DK_E
Explorer

We run it on Windows 2008 R2. It does always a rollback after 5 - 8 minutes of installation process, but the splunk,version has 6.3.0.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Splunk support said they we're going to fix this in the next release, so you could wait until the next release or you can keep trying. When I was trying to install, it would rollback about 70% of the time and hang during the installation process the other 30% of the time. We ran procmon during the install and saw the installation doing work so we left it alone and after 7 hours it finally upgraded.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I ran this in verbose mode so I could log the error and got this..

MSI (c) (94:50) [09:43:57:362]: Note: 1: 1708 
MSI (c) (94:50) [09:43:57:362]: Note: 1: 2228 2:  3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1708 
MSI (c) (94:50) [09:43:57:362]: Note: 1: 2205 2:  3: Error 
MSI (c) (94:50) [09:43:57:362]: Note: 1: 2228 2:  3: Error 4: SELECT `Message` FROM `Error` WHERE `Error` = 1709 
MSI (c) (94:50) [09:43:57:362]: Product: Splunk Enterprise -- Installation failed.

MSI (c) (94:50) [09:43:57:362]: Windows Installer installed the product. Product Name: Splunk Enterprise. Product Version: 6.4.1.0. Product Language: 1033. Manufacturer: Splunk, Inc.. Installation success or error status: 1603.

MSI (c) (94:50) [09:43:57:378]: Cleaning up uninstalled install packages, if any exist
MSI (c) (94:50) [09:43:57:378]: MainEngineThread is returning 1603
=== Verbose logging stopped: 6/7/2016  9:43:57 ===
0 Karma

skoelpin
SplunkTrust
SplunkTrust

Update:

If I started the Splunkd service when it's hung on the installation, it will bring up the Splunk 6.4 GUI and I'm able to search using the upgraded version. The only issue is when I go and cancel the install or stop it from running, Splunk will automatically roll it back and I have to use the old Splunk version again

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...