Getting Data In

Why am I getting error "Splunk Enterprise setup wizard ended prematurely" on Windows 7 32-bit English OS?

nawneel
Communicator

I am also trying to install 6.2.1 on Windows 7 English version. I had 6.1 before, but when I tried upgrading it to 6.2.1, it gave a message "splunk enterprise setup wizard ended prematurely" after running long enough. The second approach i took was to uninstall 6.1 and then do a fresh install of the 6.2.1 version, but in vain. Does any one have any idea on this?

sideview
SplunkTrust
SplunkTrust

I've seen that same error in a prior upgrade, and the somewhat surprising solution for me was to manually shutdown Splunk before running the MSI to upgrade. The MSI should be able to shutdown Splunk during the course of the installation process but for some reason it was failing and that generic error message was all that was coming back to me. I think I've seen it on two different upgrades (both were windows 7 x64 fwiw), and since then I just shutdown splunk before ever upgrading via an msi. hth.

0 Karma

brothersman
New Member

Whats odd is we upgraded 99 other servers today with no issues...but this one!

But I will try this!

0 Karma

brothersman
New Member

not work for me!

0 Karma

sideview
SplunkTrust
SplunkTrust

Interesting. O well. Good luck. One more dumb idea - have you tried running the msi as an administrator? it's maybe distantly possible they're doing the privilege escalation hoopjumping in some way that Windows 7 doesn't like.

0 Karma

brothersman
New Member

That's the first thing I tried, running as domain admin and local admin as "admin"

0 Karma

Richfez
SplunkTrust
SplunkTrust

You can't install the 64 bit version of Splunk on a 32 bit OS.

Use the 32 bit version instead.

brothersman
New Member

I downvoted this post because we are installing 64bit sf on 64bit os

0 Karma

brothersman
New Member

msiexec /i splunkforwarder-6.3.4-x64.msi /lv C:\tmp\splunkInstall.log

Below is entire log, wont let me attach files yet.
=== Logging started: 6/13/2016 14:33:45 ===
Action 14:33:45: INSTALL.
Action start 14:33:45: INSTALL.
Action 14:33:45: SetAllUsers.
Action start 14:33:45: SetAllUsers.
SetAllUsers: Info: Registry setting for current user is not found.
SetAllUsers: Info: ALLUSERS value for the existing installation: -1.
SetAllUsers: Info: Set ALLUSERS property to 1.
SetAllUsers: Info: Leave SetAllUsers: 0x0.
Action ended 14:33:45: SetAllUsers. Return value 1.
Action 14:33:45: FindRelatedProducts. Searching for related applications
Action start 14:33:45: FindRelatedProducts.
Action ended 14:33:45: FindRelatedProducts. Return value 1.
Action 14:33:45: GetPreviousSettings.
Action start 14:33:45: GetPreviousSettings.
GetPreviousSettings: Info: no installed splunk products found
GetPreviousSettings: Info: Leave GetPreviousSettings: 0x0.
Action ended 14:33:45: GetPreviousSettings. Return value 1.
Action 14:33:45: CheckSupportedOs.
Action start 14:33:45: CheckSupportedOs.
Action ended 14:33:45: CheckSupportedOs. Return value 1.
Action 14:33:45: PrepareDlg.
Action start 14:33:45: PrepareDlg.
Info 2898.For WixUI_Font_Normal textstyle, the system created a 'Tahoma' font, in 0 character set, of 13 pixels height.
Info 2898.For WixUI_Font_Bigger textstyle, the system created a 'Tahoma' font, in 0 character set, of 19 pixels height.
Action 14:33:45: PrepareDlg. Dialog created
Action ended 14:33:45: PrepareDlg. Return value 1.
Action 14:33:45: AppSearch. Searching for installed applications
Action start 14:33:45: AppSearch.
Action ended 14:33:45: AppSearch. Return value 0.
Action 14:33:45: ValidateProductID.
Action start 14:33:45: ValidateProductID.
Action ended 14:33:45: ValidateProductID. Return value 1.
Action 14:33:45: CostInitialize. Computing space requirements
Action start 14:33:45: CostInitialize.
Action ended 14:33:45: CostInitialize. Return value 1.
Action 14:33:45: FileCost. Computing space requirements
Action start 14:33:45: FileCost.
Action ended 14:33:45: FileCost. Return value 1.
Action 14:33:45: CostFinalize. Computing space requirements
Action start 14:33:45: CostFinalize.
Action ended 14:33:45: CostFinalize. Return value 1.
Action 14:33:45: UFInstallDlg.
Action start 14:33:45: UFInstallDlg.
Info 2898.For WixUI_Font_Title textstyle, the system created a 'Tahoma' font, in 0 character set, of 14 pixels height.
Action 14:33:45: UFInstallDlg. Dialog created
Info 2898.For SplunkUI_Font_Bold textstyle, the system created a 'Tahoma' font, in 0 character set, of 13 pixels height.
Info 2898.For SplunkUI_Font_Italic textstyle, the system created a 'Tahoma' font, in 0 character set, of 13 pixels height.
Action 14:33:48: DeplSrvIdxDlg. Dialog created
Action 14:33:49: ValidateAndSetDeplSrvParams.
Action start 14:33:49: ValidateAndSetDeplSrvParams.
Action ended 14:33:49: ValidateAndSetDeplSrvParams. Return value 1.
Action 14:33:49: RecvIdxDlg. Dialog created
Action 14:33:50: ValidateAndSetRecvIdxParams.
Action start 14:33:50: ValidateAndSetRecvIdxParams.
Action ended 14:33:50: ValidateAndSetRecvIdxParams. Return value 1.
Action 14:33:50: UFWarnDlg. Dialog created
Action 14:33:51: UFVerifyReadyDlg. Dialog created
Action ended 14:33:52: UFInstallDlg. Return value 1.
Action 14:33:52: ProgressDlg.
Action start 14:33:52: ProgressDlg.
Action 14:33:52: ProgressDlg. Dialog created
Action ended 14:33:52: ProgressDlg. Return value 1.
Action 14:33:52: ProgressDlg1.
Action start 14:33:52: ProgressDlg1.
Action 14:33:52: ProgressDlg1. Dialog created
Action ended 14:33:52: ProgressDlg1. Return value 1.
Action 14:33:52: ExecuteAction.
Action start 14:33:52: ExecuteAction.
Action ended 14:33:53: ExecuteAction. Return value 3.
Action 14:33:53: FatalError.
Action start 14:33:53: FatalError.
Action 14:33:53: FatalError. Dialog created
Action ended 14:33:54: FatalError. Return value 2.
Action ended 14:33:54: INSTALL. Return value 3.
Property(C): UpgradeCode = {64B13631-6664-4F23-AFE2-98FCE86920BD}
Property(C): SET_ADMIN_USER = 1
Property(C): UILicenseAgreement = 1
Property(C): InstallFlow = 1
Property(C): INSTALLDIR = C:\Program Files\SplunkUniversalForwarder\
Property(C): dirA5528701EE26FFBF346CCE20EE8ACE99 = C:\Program Files\SplunkUniversalForwarder\bin\
Property(C): dirE99B67BA83CA9B283DA87308D2AB32C0 = C:\Program Files\SplunkUniversalForwarder\bin\scripts\
Property(C): dir3E02976F57563947ADB6A8038DF4FCEF = C:\Program Files\SplunkUniversalForwarder\etc\
Property(C): dirFB7FAFCA28F7419DE35973B35C5D283E = C:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\bin\
Property(C): dirA4925C017BDFD103F37D0BDE702E9C43 = C:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\default\
Property(C): dir7C2F815EE2C9E7DBE85066CF5B056987 = C:\Program Files\SplunkUniversalForwarder\etc\apps\learned\default\
Property(C): dir28F70AA0D15CA730061DB84FFE88D805 = C:\Program Files\SplunkUniversalForwarder\etc\apps\learned\metadata\
Property(C): dir0ABBB45398994B5C89841ED05851776C = C:\Program Files\SplunkUniversalForwarder\etc\apps\search\default\
Property(C): dir66FC566CEF189328CCCC8589311D2503 = C:\Program Files\SplunkUniversalForwarder\etc\apps\search\metadata\
Property(C): dir2D2122E4CFDE8C263EEE7452554D6DA2 = C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\
Property(C): dirF389DCA026B8D0A2E829970DE12F66F0 = C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\metadata\
Property(C): dirD4A311E40878FB05D111541A6F077C82 = C:\Program Files\SplunkUniversalForwarder\etc\apps\splunk_httpinput\default\
Property(C): dir2A81299A0652E91159BE1994DD92316A = C:\Program Files\SplunkUniversalForwarder\etc\auth\
Property(C): dir67189055EBCF5D1437F0A9D30368ED9C = C:\Program Files\SplunkUniversalForwarder\etc\deployment-apps\
Property(C): dirA6241AC9F2CFDD1D7D4327FB5A124C92 = C:\Program Files\SplunkUniversalForwarder\etc\disabled-apps\
Property(C): dir96D85E5B4631FB954D7A2F05F344C017 = C:\Program Files\SplunkUniversalForwarder\etc\licenses\forwarder\
Property(C): dir3F2ED1881D5C561B698B737D96419537 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\exec\
Property(C): dir3C58D8B9DB7081CC9C009A2FA233FFFD = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\fschangemanager\
Property(C): dir623F2857FD6CE56C0C7472F3CF4B157E = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\structuredparsing\
Property(C): dirAAE2EA6FF6BFF3615E0F6ECB4F8B8317 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\tailfile\
Property(C): dir40C5047ABE9F85BC416CF37384338C22 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\TCP\
Property(C): dir500C5AB468B41B12914CAFC92914BB04 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\UDP\
Property(C): dir350E86D3D8394619D5C56BE268AB8C03 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\wineventlog\
Property(C): dir08A71AA8240CE634F2916BD8FD86AE9D = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\winparsing\
Property(C): dir36980B38D75840D0DF3C22965AFE352F = C:\Program Files\SplunkUniversalForwarder\etc\modules\parsing\
Property(C): dirEA4E77DDDE1ED87692CD92A2F7477FDA = C:\Program Files\SplunkUniversalForwarder\etc\myinstall\
Property(C): dir62FE35BBE7BD45CAEAB9D4261B2C1DA9 = C:\Program Files\SplunkUniversalForwarder\etc\shcluster\apps\
Property(C): dir7A9E1C63375946BEF53B8BCD2F9EB32B = C:\Program Files\SplunkUniversalForwarder\etc\shcluster\users\
Property(C): dir5320F257A67DB36A4CED85E00FC63DD0 = C:\Program Files\SplunkUniversalForwarder\etc\system\bin\
Property(C): dirBAC85229BB4A3494F5ECCB42AA1B824B = C:\Program Files\SplunkUniversalForwarder\etc\system\default\
Property(C): dirD3351CCE95594E87E2CC36C1024B5B4C = C:\Program Files\SplunkUniversalForwarder\etc\system\local\
Property(C): dir858D19BEE324185B277CA79FFC48EDEE = C:\Program Files\SplunkUniversalForwarder\etc\system\metadata\
Property(C): dir5083584ADFC4261D3780F7B66CB3B7B3 = C:\Program Files\SplunkUniversalForwarder\etc\system\README\
Property(C): dir087F918F10A120B6907E2460F0868A49 = C:\Program Files\SplunkUniversalForwarder\etc\system\static\
Property(C): dirCC4BF51C3FB0120CE9B785729700549B = C:\Program Files\SplunkUniversalForwarder\lib\
Property(C): dir9777D8246D1EFF4BCE1BBB3725F54761 = C:\Program Files\SplunkUniversalForwarder\share\
Property(C): dirD3369B4CFA7BF6DCB57584A7F452CA0A = C:\Program Files\SplunkUniversalForwarder\share\splunk\
Property(C): dir9DF6D6597089BA01028EE58CBBF75736 = C:\Program Files\SplunkUniversalForwarder\share\splunk\3rdparty\
Property(C): WixUIRMOption = UseRM
Property(C): _UICertFile = UICertFile
Property(C): _UIRootCertFile = UIRootCertFile
Property(C): UIMonPath = MONITOR_PATH
Property(C): UIUseLocalSystem = 1
Property(C): UIUseBundledTA = 1
Property(C): _UIWinTAPath = UIWinTAPath
Property(C): WIXUI_INSTALLDIR = INSTALLDIR
Property(C): ALLUSERS = 1
Property(C): ARPNOMODIFY = yes
Property(C): ProgramFiles64Folder = C:\Program Files\
Property(C): TARGETDIR = E:\
Property(C): SourceDir = C:\TEMP\
Property(C): dirFB744D04EDFDCD8AF58A1449ABBAD45F = C:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\
Property(C): dirB06939592AE1B7F84A5F1802888016F6 = C:\Program Files\SplunkUniversalForwarder\etc\apps\
Property(C): dir1ACCD951EA5C77FB92B36E8AB9382509 = C:\Program Files\SplunkUniversalForwarder\etc\apps\learned\
Property(C): dir302A0E4D0E8A28D4161D5640B55896DC = C:\Program Files\SplunkUniversalForwarder\etc\apps\search\
Property(C): dir060491FD1B1F02D6FE725F0B7611F71E = C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\
Property(C): dir37D95D2E12ED679D75C8A0AC58D0D14E = C:\Program Files\SplunkUniversalForwarder\etc\apps\splunk_httpinput\
Property(C): dir5D12D44E1DF9B11CFF5F78F3431780DE = C:\Program Files\SplunkUniversalForwarder\etc\licenses\
Property(C): dir4B3ADB252806E43AB420F8399AC61D45 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\
Property(C): dir613AD2632481811E0F84C80F31F4CD56 = C:\Program Files\SplunkUniversalForwarder\etc\modules\
Property(C): dir6EEC3061DFBF56B9D6D2F8CBEC90FE26 = C:\Program Files\SplunkUniversalForwarder\etc\shcluster\
Property(C): dirCFB1DCA36329665F066AABF5013AECA9 = C:\Program Files\SplunkUniversalForwarder\etc\system\
Property(C): Manufacturer = Splunk, Inc.
Property(C): ProductCode = {29032975-1994-4E51-9C9D-A2C545E735B9}
Property(C): ProductLanguage = 1033
Property(C): ProductName = UniversalForwarder
Property(C): ProductVersion = 6.3.4.0
Property(C): ARPPRODUCTICON = WixSplunkIcon
Property(C): DefaultUIFont = WixUI_Font_Normal
Property(C): WixUI_Mode = InstallDir
Property(C): ErrorDialog = ErrorDlg
Property(C): SplunkSvcName = SplunkForwarder
Property(C): UIShowTADialog = 0
Property(C): UIRecvIdxValid = 1
Property(C): DoNotInstallDrivers = 0
Property(C): SplunkX86Msi = 0
Property(C): UICustomize = 2
Property(C): AGREETOLICENSE = Yes
Property(C): LAUNCHSPLUNK = 1
Property(C): WINDOWS_TA_VERSION = 475
Property(C): os_OK = 1
Property(C): MSIRESTARTMANAGERCONTROL = Disable
Property(C): MSIDISABLERMRESTART = 1
Property(C): MSIRMSHUTDOWN = 2
Property(C): LEGACYDRV = 1
Property(C): AdminProperties = AGREETOLICENSE;CERTFILE;CERTPASSWORD;CLONEPREP;DEPLOYMENT_SERVER;DoNotInstallDrivers;ENABLEADMON;FAILCA;FORCEINSTALLDRIVERS;KEEPSPLUNKHOME;LAUNCHSPLUNK;LEGACYDRV;LOGON_PASSWORD;LOGON_USERNAME;MONITOR_PATH;NEWERVERSIONDETECTED;os_OK;OtherSplunkProductsPresent;PERFMON;PREVPRODUCTCODE;RECEIVING_INDEXER;ROOTCACERTFILE;SameProdCodeExists;SET_ADMIN_USER;SPLUNKD_PORT;SPLUNKPASSWORD;UIAdmon;UIApplicationLog;UICertFile;UICertPassword;UIConfirmCertPassword;UIConfirmDomainPassword;UIDeplSrv;UIDeplSrvPort;UIDomainAccount;UIDomainPassword;UIForwardedEventsLog;UIMonPath;UINoDeplSrvOrIndexer;UIPerfCpu;UIPerfDisk;UIPerfMemory;UIPerfNetstat;UIRecvIdx;UIRecvIdxPort;UIRootCertFile;UISecurityLog;UISetupLog;UISystemLog;UIWinTAPath;WINDOWS_TA_LOCATION;WINDOWS_TA_VERSION;WINEVENTLOG_APP_ENABLE;WINEVENTLOG_FWD_ENABLE;WINEVENTLOG_SEC_ENABLE;WINEVENTLOG_SET_ENABLE;WINEVENTLOG_SYS_ENABLE
Property(C): SecureCustomProperties = ARPNOMODIFY;NEWERVERSIONDETECTED;PREVPRODUCTCODE
Property(C): MsiHiddenProperties = LOGON_PASSWORD;SetSplunkPassword;SetupServiceConfig;SPLUNKPASSWORD
Property(C): MsiLogFileLocation = C:\splunkinstall.log
Property(C): PackageCode = {D865729F-B407-4D79-96B4-309E18136C57}
Property(C): ProductState = -1
Property(C): PackagecodeChanging = 1
Property(C): CURRENTDIRECTORY = C:\TEMP
Property(C): CLIENTUILEVEL = 0
Property(C): CLIENTPROCESSID = 7996
Property(C): MsiSystemRebootPending = 1
Property(C): VersionDatabase = 200
Property(C): VersionMsi = 5.00
Property(C): VersionNT = 601
Property(C): VersionNT64 = 601
Property(C): WindowsBuild = 7601
Property(C): ServicePackLevel = 1
Property(C): ServicePackLevelMinor = 0
Property(C): MsiNTProductType = 3
Property(C): MsiNTSuiteEnterprise = 1
Property(C): WindowsFolder = C:\Windows\
Property(C): WindowsVolume = C:\
Property(C): System64Folder = C:\Windows\system32\
Property(C): SystemFolder = C:\Windows\SysWOW64\
Property(C): RemoteAdminTS = 1
Property(C): TempFolder = C:\Users\ADMINI~1\AppData\Local\Temp\5\
Property(C): ProgramFilesFolder = C:\Program Files (x86)\
Property(C): CommonFilesFolder = C:\Program Files (x86)\Common Files\
Property(C): CommonFiles64Folder = C:\Program Files\Common Files\
Property(C): AppDataFolder = C:\Users\Administrator\AppData\Roaming\
Property(C): FavoritesFolder = C:\Users\Administrator\Favorites\
Property(C): NetHoodFolder = C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts\
Property(C): PersonalFolder = C:\Users\Administrator\Documents\
Property(C): PrintHoodFolder = C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\
Property(C): RecentFolder = C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\
Property(C): SendToFolder = C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\
Property(C): TemplateFolder = C:\ProgramData\Microsoft\Windows\Templates\
Property(C): CommonAppDataFolder = C:\ProgramData\
Property(C): LocalAppDataFolder = C:\Users\Administrator\AppData\Local\
Property(C): MyPicturesFolder = C:\Users\Administrator\Pictures\
Property(C): AdminToolsFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\
Property(C): StartupFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Property(C): ProgramMenuFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\
Property(C): StartMenuFolder = C:\ProgramData\Microsoft\Windows\Start Menu\
Property(C): DesktopFolder = C:\Users\Public\Desktop\
Property(C): FontsFolder = C:\Windows\Fonts\
Property(C): GPTSupport = 1
Property(C): OLEAdvtSupport = 1
Property(C): ShellAdvtSupport = 1
Property(C): MsiAMD64 = 6
Property(C): Msix64 = 6
Property(C): Intel = 6
Property(C): PhysicalMemory = 147446
Property(C): VirtualMemory = 133799
Property(C): AdminUser = 1
Property(C): MsiTrueAdminUser = 1
Property(C): LogonUser = xAdministrator
Property(C): UserSID = S-1-5-21-2865489601-3508374689-3744283199-500
Property(C): UserLanguageID = 1033
Property(C): ComputerName = VATERIAMVDS201
Property(C): SystemLanguageID = 1033
Property(C): ScreenX = 1664
Property(C): ScreenY = 1034
Property(C): CaptionHeight = 19
Property(C): BorderTop = 1
Property(C): BorderSide = 1
Property(C): TextHeight = 16
Property(C): TextInternalLeading = 3
Property(C): ColorBits = 16
Property(C): TTCSupport = 1
Property(C): Time = 14:33:54
Property(C): Date = 6/13/2016
Property(C): MsiNetAssemblySupport = 4.0.30319.34209
Property(C): MsiWin32AssemblySupport = 6.1.7601.17514
Property(C): RedirectedDllSupport = 2
Property(C): MsiRunningElevated = 1
Property(C): Privileged = 1
Property(C): USERNAME = Windows User
Property(C): DATABASE = C:\TEMP\splunkforwarder-6.3.4-x64.msi
Property(C): OriginalDatabase = C:\TEMP\splunkforwarder-6.3.4-x64.msi
Property(C): SOURCEDIR = C:\TEMP\
Property(C): VersionHandler = 5.00
Property(C): UILevel = 5
Property(C): ACTION = INSTALL
Property(C): EXECUTEACTION = INSTALL
Property(C): ROOTDRIVE = E:\
Property(C): CostingComplete = 1
Property(C): OutOfDiskSpace = 0
Property(C): OutOfNoRbDiskSpace = 0
Property(C): PrimaryVolumeSpaceAvailable = 0
Property(C): PrimaryVolumeSpaceRequired = 0
Property(C): PrimaryVolumeSpaceRemaining = 0
Property(C): INSTALLLEVEL = 1
Property(C): UIDeplSrvValid = 1
Property(C): WINEVENTLOG_APP_ENABLE = 1
Property(C): WINEVENTLOG_SEC_ENABLE = 1
Property(C): WINEVENTLOG_SYS_ENABLE = 1
Property(C): UINoDeplSrvOrIndexer = 1
=== Logging stopped: 6/13/2016 14:33:54 ===
MSI (c) (3C:A8) [14:33:54:115]: Product: UniversalForwarder -- Installation failed.

MSI (c) (3C:A8) [14:33:54:115]: Windows Installer installed the product. Product Name: UniversalForwarder. Product Version: 6.3.4.0. Product Language: 1033. Manufacturer: Splunk, Inc.. Installation success or error status: 1603.

0 Karma

wcolgate_splunk
Splunk Employee
Splunk Employee

Hmmmm. Can I ask you to try one more thing? Execute the following command (the logging is still very sparse and not sure why):

$ msiexec /i (path-to-msi) /l*v (path-to-logfile)

0 Karma

brothersman
New Member

C:\TEMP>msiexec /i c:\temp\splunkforwarder-6.2.4-271043-x64-release.msi /l*v C:\temp\newSplunklog.txt

0 Karma

wcolgate_splunk
Splunk Employee
Splunk Employee

That's the right command. And now, what do we have in the log file?

0 Karma

brothersman
New Member

Too many characters to post and too many answers in one day! Also cant attach not enough Karma points.

0 Karma

wcolgate_splunk
Splunk Employee
Splunk Employee

How about grabbing the 30 lines or so before the first "Return value 3"?

0 Karma

brothersman
New Member

Action 15:30:30: ProgressDlg1.
Action start 15:30:30: ProgressDlg1.
Action 15:30:30: ProgressDlg1. Dialog created
Action ended 15:30:30: ProgressDlg1. Return value 1.
MSI (c) (08:84) [15:30:30:674]: Doing action: ExecuteAction
MSI (c) (08:84) [15:30:30:674]: Note: 1: 2205 2: 3: ActionText
Action 15:30:30: ExecuteAction.
Action start 15:30:30: ExecuteAction.
MSI (c) (08:84) [15:30:30:674]: PROPERTY CHANGE: Adding SECONDSEQUENCE property. Its value is '1'.
MSI (c) (08:84) [15:30:30:674]: Grabbed execution mutex.
MSI (c) (08:84) [15:30:30:674]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (c) (08:84) [15:30:30:674]: Switching to server: INSTALLDIR="c:\Program Files\SplunkUniversalForwarder\" TARGETDIR="E:\" AGREETOLICENSE="Yes" CURRENTDIRECTORY="C:\TEMP" CLIENTUILEVEL="0" CLIENTPROCESSID="3592" USERNAME="Windows User" SOURCEDIR="c:\temp\" ACTION="INSTALL" EXECUTEACTION="INSTALL" ROOTDRIVE="E:\" INSTALLLEVEL="1" SECONDSEQUENCE="1" WINEVENTLOG_APP_ENABLE="1" WINEVENTLOG_SEC_ENABLE="1" WINEVENTLOG_SYS_ENABLE="1" ADDLOCAL=Complete

MSI (s) (90:7C) [15:30:30:674]: Running installation inside multi-package transaction c:\temp\splunkforwarder-6.2.4-271043-x64-release.msi
MSI (s) (90:7C) [15:30:30:674]: Grabbed execution mutex.
MSI (s) (90:38) [15:30:30:690]: MainEngineThread is returning 1603
MSI (s) (90:7C) [15:30:30:690]: User policy value 'DisableRollback' is 0
MSI (s) (90:7C) [15:30:30:690]: Machine policy value 'DisableRollback' is 0
MSI (s) (90:7C) [15:30:30:690]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (90:7C) [15:30:30:690]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (90:7C) [15:30:30:690]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (90:7C) [15:30:30:690]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress 3: 2
MSI (s) (90:7C) [15:30:30:690]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress 3: 2
MSI (s) (90:7C) [15:30:30:690]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI (s) (90:7C) [15:30:30:690]: Restoring environment variables
MSI (c) (08:84) [15:30:30:690]: Back from server. Return value: 1603
MSI (c) (08:84) [15:30:30:690]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI (c) (08:84) [15:30:30:690]: PROPERTY CHANGE: Deleting SECONDSEQUENCE property. Its current value is '1'.

0 Karma

wcolgate_splunk
Splunk Employee
Splunk Employee

I don't see, "return value 3" anywhere in this.

This might help you figure out specifically which action is failing or help you help us figure out what is wrong: https://technet.microsoft.com/en-us/library/cc535232.aspx

0 Karma

wcolgate_splunk
Splunk Employee
Splunk Employee

That portion of the MSI installation log does not contain enough information to be useful. For example, which action was executed?

Would you be able to enable MSI debugging: http://support.microsoft.com/kb/223300 -- and rerun the installation?

0 Karma

brothersman
New Member

Action 14:33:52: ExecuteAction.
Action start 14:33:52: ExecuteAction.
Action ended 14:33:53: ExecuteAction. Return value 3.
Action 14:33:53: FatalError.
Action start 14:33:53: FatalError.
Action 14:33:53: FatalError. Dialog created
Action ended 14:33:54: FatalError. Return value 2.
Action ended 14:33:54: INSTALL. Return value 3

0 Karma

wcolgate_splunk
Splunk Employee
Splunk Employee

Would you be able to share your MSIxxxx.log installation log file? If you cannot find the installation log file (normally in %temp% of the user that installed the SW), you can install splunk via this command line to explicitly specify a logfile:

$ msiexec /i /l*v

In that log file you would find a string that says, "Return value 3" -- just above that should be the series of events that lead up to the installation failure.

If you can share this information, we may be able to guide you.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...