Installation

Installation issue

splunk9000
New Member

I received this error message: splunk enterprise setup wizard ended prematurely because of an error. Your system has not been modified.
I use Windows Server 2012 R2. I received this error only when I selected domain\user account

Any help will be good. Thanks.

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Apparently the domain user account doesnt have permission to read and write in the splunk folder.

OR doesnt have permission to run as a service (Group Policy).
https://technet.microsoft.com/en-us/library/cc794944(v=ws.10).aspx <- allow user to run as service

Abbreviated solution:
A local administrator will need to.... go to start -> run -> gpedit.msc [click ok]

GroupPolicyObject [ComputerName] Policy -> Computer Configuration -> Windows Settings -> Security Settings ->Local Policies ->User Rights Assignment -> change "Log on as a service." to have domain user account within the list of allowed accounts.

splunk9000
New Member

I use GPO. I have the domain group "domain\Splunk Accounts". I created the "domain\Splunk" user and added it to "domain\Splunk Accounts" group, This group has "Log on as a service" rights on the server where I try to install Splunk server.

0 Karma

jkat54
SplunkTrust
SplunkTrust

So does the user have write access to program files directory?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

What version of Splunk Enterprise? Are you installing in English or another language? Does your domain user have the right permissions to install? You might have to run the installation as Administrator.

There are a few other Answers postings about the same error message:

splunk9000
New Member

Hi Chris,

  1. splunk-6.3.2-aaff59bb082c-x64-release.msi
  2. I use English system locale
  3. I use the domain admin account for installing
  4. Yes, I run splunk-6.3.2-aaff59bb082c-x64-release.msi under Administrator command prompt

Thanks,
Arthur

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...