Getting Data In

permission problem on windows with etc\system\metadata\default.meta

mataharry
Communicator

I installed Splunk Universal forwarder on Windows (2008 rc2), but when I tried to upgrade or to uninstall, it failed.

Error 1321. The Installer has insufficient privileges to modify the file D:\Program Files\SplunkUniversalForwarder\etc\system\metadata\default.meta

It seems to be linked to the MSI installer.
I checked the file it's locked, and there are no visible owner or permissions, even windows doesn't know how to display it.

Tags (3)
1 Solution

yannK
Splunk Employee
Splunk Employee

There is a workaround to fix the file permissions :

Manually updates the permissions of the $Splunk$\etc\system\metadata folder prior to upgrading/uninstall the forwarder. Set the folder to "Inherit Permissions from Parent", and after upgrade, the default.meta file was not corrupt.

View solution in original post

yannK
Splunk Employee
Splunk Employee

There is a workaround to fix the file permissions :

Manually updates the permissions of the $Splunk$\etc\system\metadata folder prior to upgrading/uninstall the forwarder. Set the folder to "Inherit Permissions from Parent", and after upgrade, the default.meta file was not corrupt.

yannK
Splunk Employee
Splunk Employee

If you have a broken instance on the latest version (6.0 currently), and want to fix it without uninstalling, here is a workaround :

previous state : splunkforwarder version 6 with the permission issue

  • stop the splunkforwarder service
  • change recursively the owner of the folder $SPLUNK_HOME\etc\system to your user or the system
  • repair the install using the MSI command line for the same version 6.0 msiexec /fa splunkforwarder-6.0-*.msi
0 Karma

mataharry
Communicator

It worked. I still don't know what causes that. Is is only with MSI installer on the command line ?

0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...