Installation

Installation issue

splunk9000
New Member

I received this error message: splunk enterprise setup wizard ended prematurely because of an error. Your system has not been modified.
I use Windows Server 2012 R2. I received this error only when I selected domain\user account

Any help will be good. Thanks.

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Apparently the domain user account doesnt have permission to read and write in the splunk folder.

OR doesnt have permission to run as a service (Group Policy).
https://technet.microsoft.com/en-us/library/cc794944(v=ws.10).aspx <- allow user to run as service

Abbreviated solution:
A local administrator will need to.... go to start -> run -> gpedit.msc [click ok]

GroupPolicyObject [ComputerName] Policy -> Computer Configuration -> Windows Settings -> Security Settings ->Local Policies ->User Rights Assignment -> change "Log on as a service." to have domain user account within the list of allowed accounts.

splunk9000
New Member

I use GPO. I have the domain group "domain\Splunk Accounts". I created the "domain\Splunk" user and added it to "domain\Splunk Accounts" group, This group has "Log on as a service" rights on the server where I try to install Splunk server.

0 Karma

jkat54
SplunkTrust
SplunkTrust

So does the user have write access to program files directory?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

What version of Splunk Enterprise? Are you installing in English or another language? Does your domain user have the right permissions to install? You might have to run the installation as Administrator.

There are a few other Answers postings about the same error message:

splunk9000
New Member

Hi Chris,

  1. splunk-6.3.2-aaff59bb082c-x64-release.msi
  2. I use English system locale
  3. I use the domain admin account for installing
  4. Yes, I run splunk-6.3.2-aaff59bb082c-x64-release.msi under Administrator command prompt

Thanks,
Arthur

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...