Installation

Difficulty on installing Splunk UF 8.2.4 on Server 2019

rajyah
Communicator

Hi everyone,

 

I'm currently having a difficulty installing a UF in one of our Microsoft Server 2019 that is residing as VM via Hyper-V.

Please do take note that this is a fresh installation of universal forwarder in this machine. Also, this server is acting as a domain controller and we would like to get its logs.

 

Kindly show me the way since I have been searching for hours and could not find a proper answer for this. Also, I would like to avoid doing a reformatting on this specific machine just to install the UF. Thank you.

 

This shows the logs:

 

12:23:30 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splunkdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:34 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splknetdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:37 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\SplunkMonitorNoHandleDrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:40 AM
C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal first-time-run --answer-yes --no-prompt >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"

This appears to be your first time running this version of Splunk.
12:23:40 AM
C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
The certificate generation script did not generate the expected certificate file:C:\Program Files\SplunkUniversalForwarder\etc\auth\server.pem. Splunkd port communication will not work.
SSL certificate generation failed.
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\i18n
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\modules\static\css
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\upload
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\search_telemetry
		Creating: C:\Program Files\SplunkUniversalForwarder\var\spool\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\spool\dirmoncache
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\authDb
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\hashDb
12:23:45 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\SplunkMonitorNoHandleDrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:47 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splknetdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:49 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splunkdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"

 

 

Labels (3)
0 Karma

jho-splunk
Splunk Employee
Splunk Employee

Hi @rajyah,

I'm afraid we'll need a Process Monitor log to troubleshoot this further, but unfortunately they're too big to attach here so I'd suggest opening a case with Splunk Support.

Cheers,

 

 - Jo.

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...