Installation

Difficulty on installing Splunk UF 8.2.4 on Server 2019

rajyah
Communicator

Hi everyone,

 

I'm currently having a difficulty installing a UF in one of our Microsoft Server 2019 that is residing as VM via Hyper-V.

Please do take note that this is a fresh installation of universal forwarder in this machine. Also, this server is acting as a domain controller and we would like to get its logs.

 

Kindly show me the way since I have been searching for hours and could not find a proper answer for this. Also, I would like to avoid doing a reformatting on this specific machine just to install the UF. Thank you.

 

This shows the logs:

 

12:23:30 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splunkdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:34 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splknetdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:37 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\SplunkMonitorNoHandleDrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:40 AM
C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal first-time-run --answer-yes --no-prompt >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"

This appears to be your first time running this version of Splunk.
12:23:40 AM
C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
The certificate generation script did not generate the expected certificate file:C:\Program Files\SplunkUniversalForwarder\etc\auth\server.pem. Splunkd port communication will not work.
SSL certificate generation failed.
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\i18n
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\modules\static\css
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\upload
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\search_telemetry
		Creating: C:\Program Files\SplunkUniversalForwarder\var\spool\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\spool\dirmoncache
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\authDb
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\hashDb
12:23:45 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\SplunkMonitorNoHandleDrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:47 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splknetdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:49 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splunkdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"

 

 

Labels (3)
0 Karma

jho-splunk
Splunk Employee
Splunk Employee

Hi @rajyah,

I'm afraid we'll need a Process Monitor log to troubleshoot this further, but unfortunately they're too big to attach here so I'd suggest opening a case with Splunk Support.

Cheers,

 

 - Jo.

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...