Installation

Error when trying to install splunk on Windows Server 2008

bbarkinwilkins
New Member

When we try to install splunk on a Windows Server 2008, we get this error message: "Splunk Installer was unable to create Splunk Services."

We get the same error when we try to have it run as either a local system account or as an administrator account.

Any ideas?

Tags (1)
0 Karma

Ed
Splunk Employee
Splunk Employee

Did the error dialog have an error code? In most cases there are two reasons why Splunk would fail to create the services:

The user credentials provided do not have permission to create the service. If it's a new account, Log On As A Service might not be granted to the account. To test, try assigning an existing service to this user. Usually this shows an error code of 1.

The Splunk service may already exist on the machine. Sometimes uninstalls will mark the service for deletion, but will not actually remove it until a reboot. Usually this shows an error code of 2.

Please let me know if either of these are the case or if it's something different.

0 Karma

Ed
Splunk Employee
Splunk Employee

Interesting. Glad you were able to get it working. If it pops up again, the MSI log and more likely the Splunk-.log in the %TEMP% folder might provide more clues. The Splunk-.log gets overwritten with each run though, so no way to travel back in time to see what happened.

0 Karma

bbarkinwilkins
New Member

Thanks for the response Ed!

We received an error code of 1. But I don't think this had anything to do with the user permissions because the installation of Splunk 4.1 worked flawlessly. It was only Splunk 4.2 that did not work.

0 Karma

bbarkinwilkins
New Member

Quick update: it appears this problem only occurs with verison 4.2. I tried installing 4.1 and it worked perfectly.

0 Karma

bbarkinwilkins
New Member

Another update: once we had 4.1 installed, we were able to upgrade to 4.2 without a problem.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...