Getting Data In

Windows 2003 universal forwarder install failure

kmattern
Builder

I've been working on this for two days. I have an older Windows 2003 web server that I would like to forward IIS log files from. I have installed the universal forwarder 6.1.0 numerous times. Each time it fails with "Splunk Installer was unable to launch Splunk's First Time Run. Error Code: 128" complete error is listed below.

Any ideas?

Event Type: Error
Event Source: SplunkUniversalForwarderInstaller
Event Category: None
Event ID: 334
Date: 5/11/2014
Time: 11:51:15 AM
User: NT AUTHORITY\SYSTEM
Computer: MID-SOUTH
Description:
The description for Event ID ( 334 ) in Source ( SplunkUniversalForwarderInstaller ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Splunk Installer was unable to launch Splunk's First Time Run.

Error Code: 128.

0 Karma

albertozanon
New Member

Same error, an old win2003 server machine refuses to install universal forwarder 6.1.3 with the same error code 128.

Any clue about this issue?

0 Karma

PeterChu
Explorer

As upper description with 6.1.1,6.1.5,6.2.1 universal forwarder, any official person can help?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...