Getting Data In
Highlighted

"Splunk Enterprise Setup Wizard ended prematurely" and 20+ ERROR messages - help?

New Member

Hi there,

do you have any idea ?

Splunk Services will not run.
Repair by Installation gets error:

alt text

Splunkd.log:

08-31-2017 18:36:09.265 +0200 INFO loader - win-service: Starting as a Windows service: will run various system checks first...
08-31-2017 18:36:09.265 +0200 INFO loader - win-service: Splunk starting as a local administrator
08-31-2017 18:36:09.265 +0200 INFO loader - Automatic migration of modular inputs
08-31-2017 18:36:10.275 +0200 ERROR loader - win-service: Error running pre-flight-checks (pclose returned 1).
08-31-2017 18:36:10.275 +0200 ERROR loader - win-service: Here is the output from running pre-flight-checks:
08-31-2017 18:36:10.275 +0200 ERROR loader - Checking critical directories... Done
08-31-2017 18:36:10.275 +0200 ERROR loader - Checking indexes...
08-31-2017 18:36:10.275 +0200 ERROR loader - Validated: _audit _blocksignature _internal _introspection _thefishbucket alerts filewatcher filialverwaltung hhc history main nagios perfmon ping
test summary transactionaldata wineventlog
08-31-2017 18:36:10.275 +0200 ERROR loader - Done
08-31-2017 18:36:10.275 +0200 ERROR loader - Traceback (most recent call last):
08-31-2017 18:36:10.275 +0200 ERROR loader - File "C:\Program Files\Splunk\Python-2.7\Lib\site-packages\splunk\clilib\cli.py", line 17, in
08-31-2017 18:36:10.275 +0200 ERROR loader - import splunk.clilib.cli
common as comm
08-31-2017 18:36:10.275 +0200 ERROR loader - File "C:\Program Files\Splunk\Python-2.7\Lib\site-packages\splunk\clilib\clicommon.py", line 8, in
08-31-2017 18:36:10.275 +0200 ERROR loader - import httplib, shutil
08-31-2017 18:36:10.275 +0200 ERROR loader - File "C:\Program Files\Splunk\Python-2.7\Lib\httplib.py", line 73, in
08-31-2017 18:36:10.275 +0200 ERROR loader - from urlparse import urlsplit
08-31-2017 18:36:10.275 +0200 ERROR loader - ImportError: cannot import name urlsplit
08-31-2017 18:36:10.275 +0200 ERROR loader - <<<<< EOF (pre-flight-checks)
08-31-2017 18:41:07.641 +0200 INFO loader - win-service: Starting as a Windows service: will run various system checks first...
08-31-2017 18:41:07.649 +0200 INFO loader - win-service: Splunk starting as a local administrator
08-31-2017 18:41:07.649 +0200 INFO loader - Automatic migration of modular inputs
08-31-2017 18:41:08.798 +0200 ERROR loader - win-service: Error running pre-flight-checks (
pclose returned 1).
08-31-2017 18:41:08.798 +0200 ERROR loader - win-service: Here is the output from running pre-flight-checks:
08-31-2017 18:41:08.798 +0200 ERROR loader - Checking critical directories... Done
08-31-2017 18:41:08.798 +0200 ERROR loader - Checking indexes...
08-31-2017 18:41:08.798 +0200 ERROR loader - Validated: audit _blocksignature _internal _introspection _thefishbucket alerts filewatcher filialverwaltung hhc history main nagios perfmon pingtest summary transactionaldata wineventlog
08-31-2017 18:41:08.798 +0200 ERROR loader - Done
08-31-2017 18:41:08.798 +0200 ERROR loader - Traceback (most recent call last):
08-31-2017 18:41:08.798 +0200 ERROR loader - File "C:\Program Files\Splunk\Python-2.7\Lib\site-packages\splunk\clilib\cli.py", line 17, in
08-31-2017 18:41:08.798 +0200 ERROR loader - import splunk.clilib.cli
common as comm
08-31-2017 18:41:08.798 +0200 ERROR loader - File "C:\Program Files\Splunk\Python-2.7\Lib\site-packages\splunk\clilib\cli_common.py", line 8, in
08-31-2017 18:41:08.798 +0200 ERROR loader - import httplib, shutil
08-31-2017 18:41:08.798 +0200 ERROR loader - File "C:\Program Files\Splunk\Python-2.7\Lib\httplib.py", line 73, in
08-31-2017 18:41:08.798 +0200 ERROR loader - from urlparse import urlsplit
08-31-2017 18:41:08.798 +0200 ERROR loader - ImportError: cannot import name urlsplit
08-31-2017 18:41:08.798 +0200 ERROR loader - <<<<< EOF (pre-flight-checks)

0 Karma
Highlighted

Re: "Splunk Enterprise Setup Wizard ended prematurely" and 20+ ERROR messages - help?

Esteemed Legend

There is a default log file in AppData/Local/Temp/splunk.log, and you can force more logging with $ msiexec /I <splunk-MSI> /l*v <log-file>. The problem is almost always that Splunk cannot write to the disk because of a permission problem.

Highlighted

Re: "Splunk Enterprise Setup Wizard ended prematurely" and 20+ ERROR messages - help?

Esteemed Legend

Did you ever get this working? What was the problem and how did you get around it? Please post here and help others!

0 Karma
Highlighted

Re: "Splunk Enterprise Setup Wizard ended prematurely" and 20+ ERROR messages - help?

New Member

This is a step-by-step solution that worked for me based on previous answers (several threads):

Local installation of the 64-bit version on a Windows 10 laptop.

  1. Move installation file (.msi) to a temporary folder:
    c:\temp\splunk-7.3.1.1-7651b7244cf2-x64-release.msi

  2. Open a command prompt (CMD) with administrative privileges and start installation with enhanced logging:
    msiexec /i c:\temp\splunk-7.3.1.1-7651b7244cf2-x64-release.msi /l*vx msiexec.log

  3. Change the default installation folder/path in setup wizard, choose a folder other than the default program folders (c:\program files, c:\program files (x86) etc.) because of possible corporate restrictions/policys (folder permissions). I created a new folder when prompted in the setup wizard: C:\Local\Program\Splunk

  4. The setup wizard then continued and installed Splunk as expected with no errors and web GUI (localhost:8000) worked fine.

I hope some of the above steps will help with any similar installation issues.

0 Karma