Installation

Installing splunk 6.2 on GERMAN Windows Server 2012 R2

datasec2
New Member

Hi there,

when installing Splunk 6.2.0-237341-x64-release on a GERMAN Windows Server 2012 R2 it breaks with error:

Action 18:26:24: SetAcls.
SetAcls: Warning: Invalid property ignored: FailCA=.
SetAcls: Info: SetAcls: Apply admin ACLS to: C:Program FilesSplunketc.
SetAcls: Info: Enter. Args: icacls, "C:Program FilesSplunketc" /T /C /grant Administrators:f
SetAcls: Info: Execute string: cmd.exe /c "icacls "C:Program FilesSplunketc" /T /C /grant Administrators:f >> "C:UsersADMINI~1.IMPAppDataLocalTempsplunk.log" 2>&1"
SetAcls: Info: WaitForSingleObject returned : 0x0
SetAcls: Info: Exit code for process : 0x534
SetAcls: Info: Leave.
SetAcls: Error: cannot set ACLs on etc folder: 0x534.
SetAcls: Error 0x80004005: Cannot set ACLs.
CustomAction SetAcls returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)
Action ended 18:26:24: InstallFinalize. Return value 3.
Action 18:26:24: Rollback. Rolling back action:
Rollback: SetAcls
Rollback: InstallSplunkService

You have to manually create local group "Administrators" with the same rights as german named group "Administratoren" to get the installer working.
It seems that the installer is not international 😉

Regards

Moritz

0 Karma

ChrisG
Splunk Employee
Splunk Employee

There are some upgrade defects in 6.2, particularly for non-English versions of Windows. See this previous Splunk Answers thread. The defects should be fixed in an upcoming maintenance release.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Note, this affects clean installs as well - not just upgrades.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...