I am also trying to install 6.2.1 on Windows 7 English version. I had 6.1 before, but when I tried upgrading it to 6.2.1, it gave a message "splunk enterprise setup wizard ended prematurely" after running long enough. The second approach i took was to uninstall 6.1 and then do a fresh install of the 6.2.1 version, but in vain. Does any one have any idea on this?
I've seen that same error in a prior upgrade, and the somewhat surprising solution for me was to manually shutdown Splunk before running the MSI to upgrade. The MSI should be able to shutdown Splunk during the course of the installation process but for some reason it was failing and that generic error message was all that was coming back to me. I think I've seen it on two different upgrades (both were windows 7 x64 fwiw), and since then I just shutdown splunk before ever upgrading via an msi. hth.
Whats odd is we upgraded 99 other servers today with no issues...but this one!
But I will try this!
not work for me!
Interesting. O well. Good luck. One more dumb idea - have you tried running the msi as an administrator? it's maybe distantly possible they're doing the privilege escalation hoopjumping in some way that Windows 7 doesn't like.
That's the first thing I tried, running as domain admin and local admin as "admin"
You can't install the 64 bit version of Splunk on a 32 bit OS.
Use the 32 bit version instead.
I downvoted this post because we are installing 64bit sf on 64bit os
msiexec /i splunkforwarder-6.3.4-x64.msi /lv C:\tmp\splunkInstall.log
Below is entire log, wont let me attach files yet.
=== Logging started: 6/13/2016 14:33:45 ===
Action 14:33:45: INSTALL.
Action start 14:33:45: INSTALL.
Action 14:33:45: SetAllUsers.
Action start 14:33:45: SetAllUsers.
SetAllUsers: Info: Registry setting for current user is not found.
SetAllUsers: Info: ALLUSERS value for the existing installation: -1.
SetAllUsers: Info: Set ALLUSERS property to 1.
SetAllUsers: Info: Leave SetAllUsers: 0x0.
Action ended 14:33:45: SetAllUsers. Return value 1.
Action 14:33:45: FindRelatedProducts. Searching for related applications
Action start 14:33:45: FindRelatedProducts.
Action ended 14:33:45: FindRelatedProducts. Return value 1.
Action 14:33:45: GetPreviousSettings.
Action start 14:33:45: GetPreviousSettings.
GetPreviousSettings: Info: no installed splunk products found
GetPreviousSettings: Info: Leave GetPreviousSettings: 0x0.
Action ended 14:33:45: GetPreviousSettings. Return value 1.
Action 14:33:45: CheckSupportedOs.
Action start 14:33:45: CheckSupportedOs.
Action ended 14:33:45: CheckSupportedOs. Return value 1.
Action 14:33:45: PrepareDlg.
Action start 14:33:45: PrepareDlg.
Info 2898.For WixUI_Font_Normal textstyle, the system created a 'Tahoma' font, in 0 character set, of 13 pixels height.
Info 2898.For WixUI_Font_Bigger textstyle, the system created a 'Tahoma' font, in 0 character set, of 19 pixels height.
Action 14:33:45: PrepareDlg. Dialog created
Action ended 14:33:45: PrepareDlg. Return value 1.
Action 14:33:45: AppSearch. Searching for installed applications
Action start 14:33:45: AppSearch.
Action ended 14:33:45: AppSearch. Return value 0.
Action 14:33:45: ValidateProductID.
Action start 14:33:45: ValidateProductID.
Action ended 14:33:45: ValidateProductID. Return value 1.
Action 14:33:45: CostInitialize. Computing space requirements
Action start 14:33:45: CostInitialize.
Action ended 14:33:45: CostInitialize. Return value 1.
Action 14:33:45: FileCost. Computing space requirements
Action start 14:33:45: FileCost.
Action ended 14:33:45: FileCost. Return value 1.
Action 14:33:45: CostFinalize. Computing space requirements
Action start 14:33:45: CostFinalize.
Action ended 14:33:45: CostFinalize. Return value 1.
Action 14:33:45: UFInstallDlg.
Action start 14:33:45: UFInstallDlg.
Info 2898.For WixUI_Font_Title textstyle, the system created a 'Tahoma' font, in 0 character set, of 14 pixels height.
Action 14:33:45: UFInstallDlg. Dialog created
Info 2898.For SplunkUI_Font_Bold textstyle, the system created a 'Tahoma' font, in 0 character set, of 13 pixels height.
Info 2898.For SplunkUI_Font_Italic textstyle, the system created a 'Tahoma' font, in 0 character set, of 13 pixels height.
Action 14:33:48: DeplSrvIdxDlg. Dialog created
Action 14:33:49: ValidateAndSetDeplSrvParams.
Action start 14:33:49: ValidateAndSetDeplSrvParams.
Action ended 14:33:49: ValidateAndSetDeplSrvParams. Return value 1.
Action 14:33:49: RecvIdxDlg. Dialog created
Action 14:33:50: ValidateAndSetRecvIdxParams.
Action start 14:33:50: ValidateAndSetRecvIdxParams.
Action ended 14:33:50: ValidateAndSetRecvIdxParams. Return value 1.
Action 14:33:50: UFWarnDlg. Dialog created
Action 14:33:51: UFVerifyReadyDlg. Dialog created
Action ended 14:33:52: UFInstallDlg. Return value 1.
Action 14:33:52: ProgressDlg.
Action start 14:33:52: ProgressDlg.
Action 14:33:52: ProgressDlg. Dialog created
Action ended 14:33:52: ProgressDlg. Return value 1.
Action 14:33:52: ProgressDlg1.
Action start 14:33:52: ProgressDlg1.
Action 14:33:52: ProgressDlg1. Dialog created
Action ended 14:33:52: ProgressDlg1. Return value 1.
Action 14:33:52: ExecuteAction.
Action start 14:33:52: ExecuteAction.
Action ended 14:33:53: ExecuteAction. Return value 3.
Action 14:33:53: FatalError.
Action start 14:33:53: FatalError.
Action 14:33:53: FatalError. Dialog created
Action ended 14:33:54: FatalError. Return value 2.
Action ended 14:33:54: INSTALL. Return value 3.
Property(C): UpgradeCode = {64B13631-6664-4F23-AFE2-98FCE86920BD}
Property(C): SET_ADMIN_USER = 1
Property(C): UILicenseAgreement = 1
Property(C): InstallFlow = 1
Property(C): INSTALLDIR = C:\Program Files\SplunkUniversalForwarder\
Property(C): dirA5528701EE26FFBF346CCE20EE8ACE99 = C:\Program Files\SplunkUniversalForwarder\bin\
Property(C): dirE99B67BA83CA9B283DA87308D2AB32C0 = C:\Program Files\SplunkUniversalForwarder\bin\scripts\
Property(C): dir3E02976F57563947ADB6A8038DF4FCEF = C:\Program Files\SplunkUniversalForwarder\etc\
Property(C): dirFB7FAFCA28F7419DE35973B35C5D283E = C:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\bin\
Property(C): dirA4925C017BDFD103F37D0BDE702E9C43 = C:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\default\
Property(C): dir7C2F815EE2C9E7DBE85066CF5B056987 = C:\Program Files\SplunkUniversalForwarder\etc\apps\learned\default\
Property(C): dir28F70AA0D15CA730061DB84FFE88D805 = C:\Program Files\SplunkUniversalForwarder\etc\apps\learned\metadata\
Property(C): dir0ABBB45398994B5C89841ED05851776C = C:\Program Files\SplunkUniversalForwarder\etc\apps\search\default\
Property(C): dir66FC566CEF189328CCCC8589311D2503 = C:\Program Files\SplunkUniversalForwarder\etc\apps\search\metadata\
Property(C): dir2D2122E4CFDE8C263EEE7452554D6DA2 = C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\
Property(C): dirF389DCA026B8D0A2E829970DE12F66F0 = C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\metadata\
Property(C): dirD4A311E40878FB05D111541A6F077C82 = C:\Program Files\SplunkUniversalForwarder\etc\apps\splunk_httpinput\default\
Property(C): dir2A81299A0652E91159BE1994DD92316A = C:\Program Files\SplunkUniversalForwarder\etc\auth\
Property(C): dir67189055EBCF5D1437F0A9D30368ED9C = C:\Program Files\SplunkUniversalForwarder\etc\deployment-apps\
Property(C): dirA6241AC9F2CFDD1D7D4327FB5A124C92 = C:\Program Files\SplunkUniversalForwarder\etc\disabled-apps\
Property(C): dir96D85E5B4631FB954D7A2F05F344C017 = C:\Program Files\SplunkUniversalForwarder\etc\licenses\forwarder\
Property(C): dir3F2ED1881D5C561B698B737D96419537 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\exec\
Property(C): dir3C58D8B9DB7081CC9C009A2FA233FFFD = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\fschangemanager\
Property(C): dir623F2857FD6CE56C0C7472F3CF4B157E = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\structuredparsing\
Property(C): dirAAE2EA6FF6BFF3615E0F6ECB4F8B8317 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\tailfile\
Property(C): dir40C5047ABE9F85BC416CF37384338C22 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\TCP\
Property(C): dir500C5AB468B41B12914CAFC92914BB04 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\UDP\
Property(C): dir350E86D3D8394619D5C56BE268AB8C03 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\wineventlog\
Property(C): dir08A71AA8240CE634F2916BD8FD86AE9D = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\winparsing\
Property(C): dir36980B38D75840D0DF3C22965AFE352F = C:\Program Files\SplunkUniversalForwarder\etc\modules\parsing\
Property(C): dirEA4E77DDDE1ED87692CD92A2F7477FDA = C:\Program Files\SplunkUniversalForwarder\etc\myinstall\
Property(C): dir62FE35BBE7BD45CAEAB9D4261B2C1DA9 = C:\Program Files\SplunkUniversalForwarder\etc\shcluster\apps\
Property(C): dir7A9E1C63375946BEF53B8BCD2F9EB32B = C:\Program Files\SplunkUniversalForwarder\etc\shcluster\users\
Property(C): dir5320F257A67DB36A4CED85E00FC63DD0 = C:\Program Files\SplunkUniversalForwarder\etc\system\bin\
Property(C): dirBAC85229BB4A3494F5ECCB42AA1B824B = C:\Program Files\SplunkUniversalForwarder\etc\system\default\
Property(C): dirD3351CCE95594E87E2CC36C1024B5B4C = C:\Program Files\SplunkUniversalForwarder\etc\system\local\
Property(C): dir858D19BEE324185B277CA79FFC48EDEE = C:\Program Files\SplunkUniversalForwarder\etc\system\metadata\
Property(C): dir5083584ADFC4261D3780F7B66CB3B7B3 = C:\Program Files\SplunkUniversalForwarder\etc\system\README\
Property(C): dir087F918F10A120B6907E2460F0868A49 = C:\Program Files\SplunkUniversalForwarder\etc\system\static\
Property(C): dirCC4BF51C3FB0120CE9B785729700549B = C:\Program Files\SplunkUniversalForwarder\lib\
Property(C): dir9777D8246D1EFF4BCE1BBB3725F54761 = C:\Program Files\SplunkUniversalForwarder\share\
Property(C): dirD3369B4CFA7BF6DCB57584A7F452CA0A = C:\Program Files\SplunkUniversalForwarder\share\splunk\
Property(C): dir9DF6D6597089BA01028EE58CBBF75736 = C:\Program Files\SplunkUniversalForwarder\share\splunk\3rdparty\
Property(C): WixUIRMOption = UseRM
Property(C): _UICertFile = UICertFile
Property(C): _UIRootCertFile = UIRootCertFile
Property(C): UIMonPath = MONITOR_PATH
Property(C): UIUseLocalSystem = 1
Property(C): UIUseBundledTA = 1
Property(C): _UIWinTAPath = UIWinTAPath
Property(C): WIXUI_INSTALLDIR = INSTALLDIR
Property(C): ALLUSERS = 1
Property(C): ARPNOMODIFY = yes
Property(C): ProgramFiles64Folder = C:\Program Files\
Property(C): TARGETDIR = E:\
Property(C): SourceDir = C:\TEMP\
Property(C): dirFB744D04EDFDCD8AF58A1449ABBAD45F = C:\Program Files\SplunkUniversalForwarder\etc\apps\introspection_generator_addon\
Property(C): dirB06939592AE1B7F84A5F1802888016F6 = C:\Program Files\SplunkUniversalForwarder\etc\apps\
Property(C): dir1ACCD951EA5C77FB92B36E8AB9382509 = C:\Program Files\SplunkUniversalForwarder\etc\apps\learned\
Property(C): dir302A0E4D0E8A28D4161D5640B55896DC = C:\Program Files\SplunkUniversalForwarder\etc\apps\search\
Property(C): dir060491FD1B1F02D6FE725F0B7611F71E = C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\
Property(C): dir37D95D2E12ED679D75C8A0AC58D0D14E = C:\Program Files\SplunkUniversalForwarder\etc\apps\splunk_httpinput\
Property(C): dir5D12D44E1DF9B11CFF5F78F3431780DE = C:\Program Files\SplunkUniversalForwarder\etc\licenses\
Property(C): dir4B3ADB252806E43AB420F8399AC61D45 = C:\Program Files\SplunkUniversalForwarder\etc\modules\input\
Property(C): dir613AD2632481811E0F84C80F31F4CD56 = C:\Program Files\SplunkUniversalForwarder\etc\modules\
Property(C): dir6EEC3061DFBF56B9D6D2F8CBEC90FE26 = C:\Program Files\SplunkUniversalForwarder\etc\shcluster\
Property(C): dirCFB1DCA36329665F066AABF5013AECA9 = C:\Program Files\SplunkUniversalForwarder\etc\system\
Property(C): Manufacturer = Splunk, Inc.
Property(C): ProductCode = {29032975-1994-4E51-9C9D-A2C545E735B9}
Property(C): ProductLanguage = 1033
Property(C): ProductName = UniversalForwarder
Property(C): ProductVersion = 6.3.4.0
Property(C): ARPPRODUCTICON = WixSplunkIcon
Property(C): DefaultUIFont = WixUI_Font_Normal
Property(C): WixUI_Mode = InstallDir
Property(C): ErrorDialog = ErrorDlg
Property(C): SplunkSvcName = SplunkForwarder
Property(C): UIShowTADialog = 0
Property(C): UIRecvIdxValid = 1
Property(C): DoNotInstallDrivers = 0
Property(C): SplunkX86Msi = 0
Property(C): UICustomize = 2
Property(C): AGREETOLICENSE = Yes
Property(C): LAUNCHSPLUNK = 1
Property(C): WINDOWS_TA_VERSION = 475
Property(C): os_OK = 1
Property(C): MSIRESTARTMANAGERCONTROL = Disable
Property(C): MSIDISABLERMRESTART = 1
Property(C): MSIRMSHUTDOWN = 2
Property(C): LEGACYDRV = 1
Property(C): AdminProperties = AGREETOLICENSE;CERTFILE;CERTPASSWORD;CLONEPREP;DEPLOYMENT_SERVER;DoNotInstallDrivers;ENABLEADMON;FAILCA;FORCEINSTALLDRIVERS;KEEPSPLUNKHOME;LAUNCHSPLUNK;LEGACYDRV;LOGON_PASSWORD;LOGON_USERNAME;MONITOR_PATH;NEWERVERSIONDETECTED;os_OK;OtherSplunkProductsPresent;PERFMON;PREVPRODUCTCODE;RECEIVING_INDEXER;ROOTCACERTFILE;SameProdCodeExists;SET_ADMIN_USER;SPLUNKD_PORT;SPLUNKPASSWORD;UIAdmon;UIApplicationLog;UICertFile;UICertPassword;UIConfirmCertPassword;UIConfirmDomainPassword;UIDeplSrv;UIDeplSrvPort;UIDomainAccount;UIDomainPassword;UIForwardedEventsLog;UIMonPath;UINoDeplSrvOrIndexer;UIPerfCpu;UIPerfDisk;UIPerfMemory;UIPerfNetstat;UIRecvIdx;UIRecvIdxPort;UIRootCertFile;UISecurityLog;UISetupLog;UISystemLog;UIWinTAPath;WINDOWS_TA_LOCATION;WINDOWS_TA_VERSION;WINEVENTLOG_APP_ENABLE;WINEVENTLOG_FWD_ENABLE;WINEVENTLOG_SEC_ENABLE;WINEVENTLOG_SET_ENABLE;WINEVENTLOG_SYS_ENABLE
Property(C): SecureCustomProperties = ARPNOMODIFY;NEWERVERSIONDETECTED;PREVPRODUCTCODE
Property(C): MsiHiddenProperties = LOGON_PASSWORD;SetSplunkPassword;SetupServiceConfig;SPLUNKPASSWORD
Property(C): MsiLogFileLocation = C:\splunkinstall.log
Property(C): PackageCode = {D865729F-B407-4D79-96B4-309E18136C57}
Property(C): ProductState = -1
Property(C): PackagecodeChanging = 1
Property(C): CURRENTDIRECTORY = C:\TEMP
Property(C): CLIENTUILEVEL = 0
Property(C): CLIENTPROCESSID = 7996
Property(C): MsiSystemRebootPending = 1
Property(C): VersionDatabase = 200
Property(C): VersionMsi = 5.00
Property(C): VersionNT = 601
Property(C): VersionNT64 = 601
Property(C): WindowsBuild = 7601
Property(C): ServicePackLevel = 1
Property(C): ServicePackLevelMinor = 0
Property(C): MsiNTProductType = 3
Property(C): MsiNTSuiteEnterprise = 1
Property(C): WindowsFolder = C:\Windows\
Property(C): WindowsVolume = C:\
Property(C): System64Folder = C:\Windows\system32\
Property(C): SystemFolder = C:\Windows\SysWOW64\
Property(C): RemoteAdminTS = 1
Property(C): TempFolder = C:\Users\ADMINI~1\AppData\Local\Temp\5\
Property(C): ProgramFilesFolder = C:\Program Files (x86)\
Property(C): CommonFilesFolder = C:\Program Files (x86)\Common Files\
Property(C): CommonFiles64Folder = C:\Program Files\Common Files\
Property(C): AppDataFolder = C:\Users\Administrator\AppData\Roaming\
Property(C): FavoritesFolder = C:\Users\Administrator\Favorites\
Property(C): NetHoodFolder = C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts\
Property(C): PersonalFolder = C:\Users\Administrator\Documents\
Property(C): PrintHoodFolder = C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\
Property(C): RecentFolder = C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\
Property(C): SendToFolder = C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\
Property(C): TemplateFolder = C:\ProgramData\Microsoft\Windows\Templates\
Property(C): CommonAppDataFolder = C:\ProgramData\
Property(C): LocalAppDataFolder = C:\Users\Administrator\AppData\Local\
Property(C): MyPicturesFolder = C:\Users\Administrator\Pictures\
Property(C): AdminToolsFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\
Property(C): StartupFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Property(C): ProgramMenuFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\
Property(C): StartMenuFolder = C:\ProgramData\Microsoft\Windows\Start Menu\
Property(C): DesktopFolder = C:\Users\Public\Desktop\
Property(C): FontsFolder = C:\Windows\Fonts\
Property(C): GPTSupport = 1
Property(C): OLEAdvtSupport = 1
Property(C): ShellAdvtSupport = 1
Property(C): MsiAMD64 = 6
Property(C): Msix64 = 6
Property(C): Intel = 6
Property(C): PhysicalMemory = 147446
Property(C): VirtualMemory = 133799
Property(C): AdminUser = 1
Property(C): MsiTrueAdminUser = 1
Property(C): LogonUser = xAdministrator
Property(C): UserSID = S-1-5-21-2865489601-3508374689-3744283199-500
Property(C): UserLanguageID = 1033
Property(C): ComputerName = VATERIAMVDS201
Property(C): SystemLanguageID = 1033
Property(C): ScreenX = 1664
Property(C): ScreenY = 1034
Property(C): CaptionHeight = 19
Property(C): BorderTop = 1
Property(C): BorderSide = 1
Property(C): TextHeight = 16
Property(C): TextInternalLeading = 3
Property(C): ColorBits = 16
Property(C): TTCSupport = 1
Property(C): Time = 14:33:54
Property(C): Date = 6/13/2016
Property(C): MsiNetAssemblySupport = 4.0.30319.34209
Property(C): MsiWin32AssemblySupport = 6.1.7601.17514
Property(C): RedirectedDllSupport = 2
Property(C): MsiRunningElevated = 1
Property(C): Privileged = 1
Property(C): USERNAME = Windows User
Property(C): DATABASE = C:\TEMP\splunkforwarder-6.3.4-x64.msi
Property(C): OriginalDatabase = C:\TEMP\splunkforwarder-6.3.4-x64.msi
Property(C): SOURCEDIR = C:\TEMP\
Property(C): VersionHandler = 5.00
Property(C): UILevel = 5
Property(C): ACTION = INSTALL
Property(C): EXECUTEACTION = INSTALL
Property(C): ROOTDRIVE = E:\
Property(C): CostingComplete = 1
Property(C): OutOfDiskSpace = 0
Property(C): OutOfNoRbDiskSpace = 0
Property(C): PrimaryVolumeSpaceAvailable = 0
Property(C): PrimaryVolumeSpaceRequired = 0
Property(C): PrimaryVolumeSpaceRemaining = 0
Property(C): INSTALLLEVEL = 1
Property(C): UIDeplSrvValid = 1
Property(C): WINEVENTLOG_APP_ENABLE = 1
Property(C): WINEVENTLOG_SEC_ENABLE = 1
Property(C): WINEVENTLOG_SYS_ENABLE = 1
Property(C): UINoDeplSrvOrIndexer = 1
=== Logging stopped: 6/13/2016 14:33:54 ===
MSI (c) (3C:A8) [14:33:54:115]: Product: UniversalForwarder -- Installation failed.
MSI (c) (3C:A8) [14:33:54:115]: Windows Installer installed the product. Product Name: UniversalForwarder. Product Version: 6.3.4.0. Product Language: 1033. Manufacturer: Splunk, Inc.. Installation success or error status: 1603.
Hmmmm. Can I ask you to try one more thing? Execute the following command (the logging is still very sparse and not sure why):
$ msiexec /i (path-to-msi) /l*v (path-to-logfile)
C:\TEMP>msiexec /i c:\temp\splunkforwarder-6.2.4-271043-x64-release.msi /l*v C:\temp\newSplunklog.txt
That's the right command. And now, what do we have in the log file?
Too many characters to post and too many answers in one day! Also cant attach not enough Karma points.
How about grabbing the 30 lines or so before the first "Return value 3"?
Action 15:30:30: ProgressDlg1.
Action start 15:30:30: ProgressDlg1.
Action 15:30:30: ProgressDlg1. Dialog created
Action ended 15:30:30: ProgressDlg1. Return value 1.
MSI (c) (08:84) [15:30:30:674]: Doing action: ExecuteAction
MSI (c) (08:84) [15:30:30:674]: Note: 1: 2205 2: 3: ActionText
Action 15:30:30: ExecuteAction.
Action start 15:30:30: ExecuteAction.
MSI (c) (08:84) [15:30:30:674]: PROPERTY CHANGE: Adding SECONDSEQUENCE property. Its value is '1'.
MSI (c) (08:84) [15:30:30:674]: Grabbed execution mutex.
MSI (c) (08:84) [15:30:30:674]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (c) (08:84) [15:30:30:674]: Switching to server: INSTALLDIR="c:\Program Files\SplunkUniversalForwarder\" TARGETDIR="E:\" AGREETOLICENSE="Yes" CURRENTDIRECTORY="C:\TEMP" CLIENTUILEVEL="0" CLIENTPROCESSID="3592" USERNAME="Windows User" SOURCEDIR="c:\temp\" ACTION="INSTALL" EXECUTEACTION="INSTALL" ROOTDRIVE="E:\" INSTALLLEVEL="1" SECONDSEQUENCE="1" WINEVENTLOG_APP_ENABLE="1" WINEVENTLOG_SEC_ENABLE="1" WINEVENTLOG_SYS_ENABLE="1" ADDLOCAL=Complete
MSI (s) (90:7C) [15:30:30:674]: Running installation inside multi-package transaction c:\temp\splunkforwarder-6.2.4-271043-x64-release.msi
MSI (s) (90:7C) [15:30:30:674]: Grabbed execution mutex.
MSI (s) (90:38) [15:30:30:690]: MainEngineThread is returning 1603
MSI (s) (90:7C) [15:30:30:690]: User policy value 'DisableRollback' is 0
MSI (s) (90:7C) [15:30:30:690]: Machine policy value 'DisableRollback' is 0
MSI (s) (90:7C) [15:30:30:690]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (90:7C) [15:30:30:690]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (90:7C) [15:30:30:690]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (90:7C) [15:30:30:690]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress 3: 2
MSI (s) (90:7C) [15:30:30:690]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress 3: 2
MSI (s) (90:7C) [15:30:30:690]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI (s) (90:7C) [15:30:30:690]: Restoring environment variables
MSI (c) (08:84) [15:30:30:690]: Back from server. Return value: 1603
MSI (c) (08:84) [15:30:30:690]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI (c) (08:84) [15:30:30:690]: PROPERTY CHANGE: Deleting SECONDSEQUENCE property. Its current value is '1'.
I don't see, "return value 3" anywhere in this.
This might help you figure out specifically which action is failing or help you help us figure out what is wrong: https://technet.microsoft.com/en-us/library/cc535232.aspx
That portion of the MSI installation log does not contain enough information to be useful. For example, which action was executed?
Would you be able to enable MSI debugging: http://support.microsoft.com/kb/223300 -- and rerun the installation?
Action 14:33:52: ExecuteAction.
Action start 14:33:52: ExecuteAction.
Action ended 14:33:53: ExecuteAction. Return value 3.
Action 14:33:53: FatalError.
Action start 14:33:53: FatalError.
Action 14:33:53: FatalError. Dialog created
Action ended 14:33:54: FatalError. Return value 2.
Action ended 14:33:54: INSTALL. Return value 3
Would you be able to share your MSIxxxx.log installation log file? If you cannot find the installation log file (normally in %temp% of the user that installed the SW), you can install splunk via this command line to explicitly specify a logfile:
$ msiexec /i /l*v
In that log file you would find a string that says, "Return value 3" -- just above that should be the series of events that lead up to the installation failure.
If you can share this information, we may be able to guide you.