Getting Data In

unable to install universal forwarder windows 10

isaacso
Engager

Every time i try to install the universal forwarder on a windows 10 64bit machine it ends prematurely immediately. When i check the event logs i see the Event ID's 1033 (with status code 1603) and 11708 (Product: UniversalForwarder -- Installation failed.).

0 Karma

jhornsby_splunk
Splunk Employee
Splunk Employee

Hi @isaacso,

Please see the following for instructions on how to troubleshoot MSI installation failure: https://helgeklein.com/blog/2012/02/how-to-troubleshoot-failed-msi-installs/

Once you have them, please paste the lines preceding "return value 3" here so that we can further help you.

Cheers,

- Jo.

0 Karma

isaacso
Engager

Part 2:

MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\Users\Public\Desktop
MSI (c) (68:00) [12:52:51:702]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
MSI (c) (68:00) [12:52:51:702]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MSI (c) (68:00) [12:52:51:702]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
MSI (c) (68:00) [12:52:51:702]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Roaming\Microsoft\Windows\Start Menu
MSI (c) (68:00) [12:52:51:702]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\Desktop
MSI (c) (68:00) [12:52:51:702]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Templates
MSI (c) (68:00) [12:52:51:702]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\Fonts
MSI (c) (68:00) [12:52:51:703]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
MSI (c) (68:00) [12:52:51:709]: MSI_LUA: Setting AdminUser property to 1 because this is the client or the user has already permitted elevation
MSI (c) (68:00) [12:52:51:709]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.
MSI (c) (68:00) [12:52:51:709]: PROPERTY CHANGE: Adding MsiRunningElevated property. Its value is '1'.
MSI (c) (68:00) [12:52:51:709]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (c) (68:00) [12:52:51:709]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (c) (68:00) [12:52:51:709]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'Izzy'.
MSI (c) (68:00) [12:52:51:709]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
MSI (c) (68:00) [12:52:51:709]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'C:\Users\Izzy\Downloads\splunkforwarder-8.0.3-a6754d8441bf-x64-release (1).msi'.
MSI (c) (68:00) [12:52:51:709]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'C:\Users\Izzy\Downloads\splunkforwarder-8.0.3-a6754d8441bf-x64-release (1).msi'.
MSI (c) (68:00) [12:52:51:709]: Machine policy value 'MsiDisableEmbeddedUI' is 0
MSI (c) (68:00) [12:52:51:709]: PROPERTY CHANGE: Adding SourceDir property. Its value is 'C:\Users\Izzy\Downloads\'.
MSI (c) (68:00) [12:52:51:709]: PROPERTY CHANGE: Adding SOURCEDIR property. Its value is 'C:\Users\Izzy\Downloads\'.
MSI (c) (68:1C) [12:52:51:710]: PROPERTY CHANGE: Adding VersionHandler property. Its value is '5.00'.
=== Logging started: 5/6/2020 12:52:51 ===
MSI (c) (68:00) [12:52:51:718]: Note: 1: 2205 2: 3: PatchPackage
MSI (c) (68:00) [12:52:51:718]: Machine policy value 'DisableRollback' is 0
MSI (c) (68:00) [12:52:51:718]: User policy value 'DisableRollback' is 0
MSI (c) (68:00) [12:52:51:718]: PROPERTY CHANGE: Adding UILevel property. Its value is '5'.
MSI (c) (68:00) [12:52:51:719]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038
MSI (c) (68:00) [12:52:51:719]: Note: 1: 2205 2: 3: LaunchCondition
MSI (c) (68:00) [12:52:51:719]: Note: 1: 2228 2: 3: LaunchCondition 4: SELECT Condition FROM LaunchCondition
MSI (c) (68:00) [12:52:51:719]: APPCOMPAT: [DetectVersionLaunchCondition] Failed to initialize pRecErr.
MSI (c) (68:00) [12:52:51:720]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (c) (68:00) [12:52:51:720]: Doing action: INSTALL
MSI (c) (68:00) [12:52:51:720]: Note: 1: 2205 2: 3: ActionText
Action 12:52:51: INSTALL.
Action start 12:52:51: INSTALL.
MSI (c) (68:00) [12:52:51:720]: UI Sequence table 'InstallUISequence' is present and populated.
MSI (c) (68:00) [12:52:51:720]: Running UISequence
MSI (c) (68:00) [12:52:51:720]: PROPERTY CHANGE: Adding EXECUTEACTION property. Its value is 'INSTALL'.
MSI (c) (68:00) [12:52:51:720]: Doing action: SetAllUsers
MSI (c) (68:00) [12:52:51:720]: Note: 1: 2205 2: 3: ActionText
Action 12:52:51: SetAllUsers.
Action start 12:52:51: SetAllUsers.
MSI (c) (68:00) [12:52:51:722]: Creating MSIHANDLE (1) of type 790542 for thread 8960
MSI (c) (68:D4) [12:52:51:724]: Invoking remote custom action. DLL: C:\Users\Izzy\AppData\Local\Temp\MSI41D4.tmp, Entrypoint: SetAllUsersCA
MSI (c) (68:28) [12:52:51:726]: Cloaking enabled.
MSI (c) (68:28) [12:52:51:726]: Attempting to enable all disabled privileges before calling Install on Server
MSI (c) (68:28) [12:52:51:726]: Connected to service for CA interface.
MSI (c) (68!94) [12:52:51:846]: Creating MSIHANDLE (2) of type 790541 for thread 15764
MSI (c) (68!94) [12:52:51:846]: Creating MSIHANDLE (3) of type 790531 for thread 15764
SetAllUsers: Debug: Num of subkeys found: 3.
MSI (c) (68!94) [12:52:51:846]: Closing MSIHANDLE (3) of type 790531 for thread 15764
MSI (c) (68!94) [12:52:51:847]: Creating MSIHANDLE (4) of type 790531 for thread 15764
SetAllUsers: Info: Previously installed Splunk product is not found.
MSI (c) (68!94) [12:52:51:847]: Closing MSIHANDLE (4) of type 790531 for thread 15764
MSI (c) (68!94) [12:52:51:847]: Creating MSIHANDLE (5) of type 790531 for thread 15764
SetAllUsers: Error: Failed SetAllUsers: 0x2.
MSI (c) (68!94) [12:52:51:847]: Closing MSIHANDLE (5) of type 790531 for thread 15764
MSI (c) (68!94) [12:52:51:847]: Creating MSIHANDLE (6) of type 790531 for thread 15764
SetAllUsers: Info: Leave SetAllUsers: 0x80004005.
MSI (c) (68!94) [12:52:51:847]: Closing MSIHANDLE (6) of type 790531 for thread 15764
MSI (c) (68!94) [12:52:51:848]: Closing MSIHANDLE (2) of type 790541 for thread 15764
CustomAction SetAllUsers returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)
MSI (c) (68:D4) [12:52:51:849]: Closing MSIHANDLE (1) of type 790542 for thread 8960
Action ended 12:52:51: SetAllUsers. Return value 3.

0 Karma

jhornsby_splunk
Splunk Employee
Splunk Employee

Hi @isaacso,

Interesting. That logging is pointing to us having a problem with something beneath HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products in the Registry. Do you think you'd be able export both that and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Installer\Products and attach them here?

Cheers,

- Jo.

0 Karma

isaacso
Engager

For some odd reason there is only this one "HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\".

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products]

[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\83C33F0CC54320C41B16118339052C5A]
"ProductName"="GoTo Opener"
"PackageCode"="19F43E00C44628A4F877533A4F925965"
"Language"=dword:00000409
"Version"=dword:01000215
"Assignment"=dword:00000000
"AdvertiseFlags"=dword:00000184
"ProductIcon"=hex(2):25,00,41,00,50,00,50,00,44,00,41,00,54,00,41,00,25,00,5c,\
00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,5c,00,49,00,6e,00,\
73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,5c,00,7b,00,43,00,30,00,46,00,33,\
00,33,00,43,00,33,00,38,00,2d,00,33,00,34,00,35,00,43,00,2d,00,34,00,43,00,\
30,00,32,00,2d,00,42,00,31,00,36,00,31,00,2d,00,31,00,31,00,33,00,38,00,39,\
00,33,00,35,00,30,00,43,00,32,00,41,00,35,00,7d,00,5c,00,69,00,63,00,6f,00,\
6e,00,2e,00,69,00,63,00,6f,00,00,00
"InstanceType"=dword:00000000
"AuthorizedLUAApp"=dword:00000000
"DeploymentFlags"=dword:00000002
"Clients"=hex(7):3a,00,00,00,00,00

[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\83C33F0CC54320C41B16118339052C5A\SourceList]
"PackageName"="GoToOpener.msi"
"LastUsedSource"=hex(2):6e,00,3b,00,31,00,3b,00,43,00,3a,00,5c,00,55,00,73,00,\
65,00,72,00,73,00,5c,00,49,00,7a,00,7a,00,79,00,5c,00,41,00,70,00,70,00,44,\
00,61,00,74,00,61,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,5c,00,54,00,65,00,\
6d,00,70,00,5c,00,42,00,33,00,44,00,32,00,45,00,42,00,39,00,33,00,2d,00,33,\
00,42,00,30,00,42,00,2d,00,34,00,44,00,37,00,33,00,2d,00,41,00,39,00,45,00,\
35,00,2d,00,35,00,45,00,38,00,31,00,42,00,43,00,32,00,36,00,33,00,42,00,46,\
00,41,00,5c,00,00,00

[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\83C33F0CC54320C41B16118339052C5A\SourceList\Media]
"DiskPrompt"="GoTo Opener Installation [1]"
"1"=";CD-ROM #1"

[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\83C33F0CC54320C41B16118339052C5A\SourceList\Net]
"1"=hex(2):43,00,3a,00,5c,00,55,00,73,00,65,00,72,00,73,00,5c,00,49,00,7a,00,\
7a,00,79,00,5c,00,41,00,70,00,70,00,44,00,61,00,74,00,61,00,5c,00,4c,00,6f,\
00,63,00,61,00,6c,00,5c,00,54,00,65,00,6d,00,70,00,5c,00,42,00,33,00,44,00,\
32,00,45,00,42,00,39,00,33,00,2d,00,33,00,42,00,30,00,42,00,2d,00,34,00,44,\
00,37,00,33,00,2d,00,41,00,39,00,45,00,35,00,2d,00,35,00,45,00,38,00,31,00,\
42,00,43,00,32,00,36,00,33,00,42,00,46,00,41,00,5c,00,00,00

[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\8A1F6DF90555FA64589072D10F7E865B]
"ProductName"="Dual-Core Optimizer"
"PackageCode"="129C173017519E24A8AE69955D4679DB"
"Language"=dword:00000409
"Version"=dword:01010004
"Assignment"=dword:00000000
"AdvertiseFlags"=dword:00000184
"ProductIcon"=hex(2):25,00,41,00,50,00,50,00,44,00,41,00,54,00,41,00,25,00,5c,\
00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,5c,00,49,00,6e,00,\
73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,5c,00,7b,00,39,00,46,00,44,00,36,\
00,46,00,31,00,41,00,38,00,2d,00,35,00,35,00,35,00,30,00,2d,00,34,00,36,00,\
41,00,46,00,2d,00,38,00,35,00,30,00,39,00,2d,00,32,00,37,00,31,00,44,00,46,\
00,30,00,45,00,37,00,36,00,38,00,42,00,35,00,7d,00,5c,00,41,00,52,00,50,00,\
50,00,52,00,4f,00,44,00,55,00,43,00,54,00,49,00,43,00,4f,00,4e,00,2e,00,65,\
00,78,00,65,00,00,00
"InstanceType"=dword:00000000
"AuthorizedLUAApp"=dword:00000000
"DeploymentFlags"=dword:00000003
"Clients"=hex(7):3a,00,00,00,00,00

[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\8A1F6DF90555FA64589072D10F7E865B\SourceList]
"PackageName"="Dual-Core Optimizer.msi"
"LastUsedSource"=hex(2):6e,00,3b,00,31,00,3b,00,43,00,3a,00,5c,00,55,00,73,00,\
65,00,72,00,73,00,5c,00,49,00,7a,00,7a,00,79,00,5c,00,41,00,70,00,70,00,44,\
00,61,00,74,00,61,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,5c,00,44,00,6f,00,\
77,00,6e,00,6c,00,6f,00,61,00,64,00,65,00,64,00,20,00,49,00,6e,00,73,00,74,\
00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,73,00,5c,00,7b,00,30,00,\
33,00,37,00,31,00,43,00,39,00,32,00,31,00,2d,00,31,00,35,00,37,00,31,00,2d,\
00,34,00,32,00,45,00,39,00,2d,00,38,00,41,00,45,00,41,00,2d,00,39,00,36,00,\
35,00,39,00,44,00,35,00,36,00,34,00,39,00,37,00,42,00,44,00,7d,00,5c,00,00,\
00

[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\8A1F6DF90555FA64589072D10F7E865B\SourceList\Media]
"DiskPrompt"="[1]"
"1"="DISK1;1"

[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\8A1F6DF90555FA64589072D10F7E865B\SourceList\Net]
"1"=hex(2):43,00,3a,00,5c,00,55,00,73,00,65,00,72,00,73,00,5c,00,49,00,7a,00,\
7a,00,79,00,5c,00,41,00,70,00,70,00,44,00,61,00,74,00,61,00,5c,00,4c,00,6f,\
00,63,00,61,00,6c,00,5c,00,44,00,6f,00,77,00,6e,00,6c,00,6f,00,61,00,64,00,\
65,00,64,00,20,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,\
00,6f,00,6e,00,73,00,5c,00,7b,00,30,00,33,00,37,00,31,00,43,00,39,00,32,00,\
31,00,2d,00,31,00,35,00,37,00,31,00,2d,00,34,00,32,00,45,00,39,00,2d,00,38,\
00,41,00,45,00,41,00,2d,00,39,00,36,00,35,00,39,00,44,00,35,00,36,00,34,00,\
39,00,37,00,42,00,44,00,7d,00,5c,00,00,00

[HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\8B17357F59074B5F87FBCDE4D112027B]
"Version"=dword:02000000

0 Karma

jhornsby_splunk
Splunk Employee
Splunk Employee

Hi @isaacso,

Okay, I think I see the problem. Could you create a dummy string value named ProductName underneath the key HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\8B17357F59074B5F87FBCDE4D112027B and then retry the installer. It doesn't matter what the value is---it can be empty.

If it still fails, please repeat the same steps to diagnose.

Cheers,

- Jo.

isaacso
Engager

Worked!! thank you so much!

0 Karma

shivanshu1593
Contributor

@isaacso, if it worked then please accept it as the answer to help others, if they run in the same issue in the future.

Thank you,

0 Karma

isaacso
Engager

how do i accept it as an answer?

0 Karma

jhornsby_splunk
Splunk Employee
Splunk Employee

That's great news! &:D

0 Karma

isaacso
Engager

Here you go, thanks for the help! posting it in 2 parts as its very large

Part 1:

=== Verbose logging started: 5/6/2020 12:52:51 Build type: SHIP UNICODE 5.00.10011.00 Calling process: C:\WINDOWS\system32\msiexec.exe ===
MSI (c) (68:1C) [12:52:51:357]: Font created. Charset: Req=0, Ret=0, Font: Req=MS Shell Dlg, Ret=MS Shell Dlg

MSI (c) (68:1C) [12:52:51:357]: Font created. Charset: Req=0, Ret=0, Font: Req=MS Shell Dlg, Ret=MS Shell Dlg

MSI (c) (68:00) [12:52:51:366]: Resetting cached policy values
MSI (c) (68:00) [12:52:51:366]: Machine policy value 'Debug' is 0
MSI (c) (68:00) [12:52:51:366]: ******* RunEngine:
******* Product: C:\Users\Izzy\Downloads\splunkforwarder-8.0.3-a6754d8441bf-x64-release (1).msi
******* Action:
******* CommandLine: **********
MSI (c) (68:00) [12:52:51:367]: Machine policy value 'DisableUserInstalls' is 0
MSI (c) (68:00) [12:52:51:376]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer 3: 2
MSI (c) (68:00) [12:52:51:376]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'C:\Users\Izzy\Downloads\splunkforwarder-8.0.3-a6754d8441bf-x64-release (1).msi' against software restriction policy
MSI (c) (68:00) [12:52:51:377]: SOFTWARE RESTRICTION POLICY: C:\Users\Izzy\Downloads\splunkforwarder-8.0.3-a6754d8441bf-x64-release (1).msi has a digital signature
MSI (c) (68:00) [12:52:51:643]: SOFTWARE RESTRICTION POLICY: C:\Users\Izzy\Downloads\splunkforwarder-8.0.3-a6754d8441bf-x64-release (1).msi is permitted to run at the 'unrestricted' authorization level.
MSI (c) (68:00) [12:52:51:686]: Cloaking enabled.
MSI (c) (68:00) [12:52:51:686]: Attempting to enable all disabled privileges before calling Install on Server
MSI (c) (68:00) [12:52:51:687]: End dialog not enabled
MSI (c) (68:00) [12:52:51:687]: Original package ==> C:\Users\Izzy\Downloads\splunkforwarder-8.0.3-a6754d8441bf-x64-release (1).msi
MSI (c) (68:00) [12:52:51:687]: Package we're running from ==> C:\Users\Izzy\Downloads\splunkforwarder-8.0.3-a6754d8441bf-x64-release (1).msi
MSI (c) (68:00) [12:52:51:690]: APPCOMPAT: Compatibility mode property overrides found.
MSI (c) (68:00) [12:52:51:690]: APPCOMPAT: looking for appcompat database entry with ProductCode '{BCEE3886-C35D-49BE-8FD2-6658AF8C5963}'.
MSI (c) (68:00) [12:52:51:690]: APPCOMPAT: no matching ProductCode found in database.
MSI (c) (68:00) [12:52:51:696]: MSCOREE not loaded loading copy from system32
MSI (c) (68:00) [12:52:51:698]: Machine policy value 'TransformsSecure' is 0
MSI (c) (68:00) [12:52:51:698]: User policy value 'TransformsAtSource' is 0
MSI (c) (68:00) [12:52:51:698]: Machine policy value 'DisablePatch' is 0
MSI (c) (68:00) [12:52:51:698]: Machine policy value 'AllowLockdownPatch' is 0
MSI (c) (68:00) [12:52:51:698]: Machine policy value 'DisableLUAPatching' is 0
MSI (c) (68:00) [12:52:51:698]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (c) (68:00) [12:52:51:698]: Enabling baseline caching for this transaction since all active patches are MSI 3.0 style MSPs or at least one MSI 3.0 minor update patch is active
MSI (c) (68:00) [12:52:51:699]: APPCOMPAT: looking for appcompat database entry with ProductCode '{BCEE3886-C35D-49BE-8FD2-6658AF8C5963}'.
MSI (c) (68:00) [12:52:51:699]: APPCOMPAT: no matching ProductCode found in database.
MSI (c) (68:00) [12:52:51:699]: Transforms are not secure.
MSI (c) (68:00) [12:52:51:699]: PROPERTY CHANGE: Adding MsiLogFileLocation property. Its value is 'C:\Temp\log2.log'.
MSI (c) (68:00) [12:52:51:699]: Command Line: CURRENTDIRECTORY=C:\WINDOWS\system32 CLIENTUILEVEL=0 CLIENTPROCESSID=11112
MSI (c) (68:00) [12:52:51:699]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{485AFAA6-F684-43FC-9B92-52F081A065EE}'.
MSI (c) (68:00) [12:52:51:699]: Product Code passed to Engine.Initialize: ''
MSI (c) (68:00) [12:52:51:699]: Product Code from property table before transforms: '{BCEE3886-C35D-49BE-8FD2-6658AF8C5963}'
MSI (c) (68:00) [12:52:51:699]: Product Code from property table after transforms: '{BCEE3886-C35D-49BE-8FD2-6658AF8C5963}'
MSI (c) (68:00) [12:52:51:699]: Product not registered: beginning first-time install
MSI (c) (68:00) [12:52:51:699]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (c) (68:00) [12:52:51:699]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (c) (68:00) [12:52:51:699]: User policy value 'SearchOrder' is 'nmu'
MSI (c) (68:00) [12:52:51:699]: Adding new sources is allowed.
MSI (c) (68:00) [12:52:51:699]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (c) (68:00) [12:52:51:699]: Package name extracted from package path: 'splunkforwarder-8.0.3-a6754d8441bf-x64-release (1).msi'
MSI (c) (68:00) [12:52:51:699]: Package to be registered: 'splunkforwarder-8.0.3-a6754d8441bf-x64-release (1).msi'
MSI (c) (68:00) [12:52:51:699]: Note: 1: 2205 2: 3: Error
MSI (c) (68:00) [12:52:51:700]: Note: 1: 2262 2: AdminProperties 3: -2147287038
MSI (c) (68:00) [12:52:51:700]: Machine policy value 'DisableMsi' is 0
MSI (c) (68:00) [12:52:51:700]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (c) (68:00) [12:52:51:700]: User policy value 'AlwaysInstallElevated' is 0
MSI (c) (68:00) [12:52:51:700]: Product installation will be elevated because user is admin and product is being installed per-machine.
MSI (c) (68:00) [12:52:51:700]: Running product '{BCEE3886-C35D-49BE-8FD2-6658AF8C5963}' with elevated privileges: Product is assigned.
MSI (c) (68:00) [12:52:51:700]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'C:\WINDOWS\system32'.
MSI (c) (68:00) [12:52:51:700]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '0'.
MSI (c) (68:00) [12:52:51:700]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '11112'.
MSI (c) (68:00) [12:52:51:700]: TRANSFORMS property is now:
MSI (c) (68:00) [12:52:51:700]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '200'.
MSI (c) (68:00) [12:52:51:700]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Roaming
MSI (c) (68:00) [12:52:51:700]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\Favorites
MSI (c) (68:00) [12:52:51:700]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Roaming\Microsoft\Windows\Network Shortcuts
MSI (c) (68:00) [12:52:51:700]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\Documents
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Roaming\Microsoft\Windows\Recent
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Roaming\Microsoft\Windows\SendTo
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Roaming\Microsoft\Windows\Templates
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\ProgramData
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\AppData\Local
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\Users\Izzy\Pictures
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs
MSI (c) (68:00) [12:52:51:701]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!