Installation

Installing splunk 6.2 on GERMAN Windows Server 2012 R2

datasec2
New Member

Hi there,

when installing Splunk 6.2.0-237341-x64-release on a GERMAN Windows Server 2012 R2 it breaks with error:

Action 18:26:24: SetAcls.
SetAcls: Warning: Invalid property ignored: FailCA=.
SetAcls: Info: SetAcls: Apply admin ACLS to: C:Program FilesSplunketc.
SetAcls: Info: Enter. Args: icacls, "C:Program FilesSplunketc" /T /C /grant Administrators:f
SetAcls: Info: Execute string: cmd.exe /c "icacls "C:Program FilesSplunketc" /T /C /grant Administrators:f >> "C:UsersADMINI~1.IMPAppDataLocalTempsplunk.log" 2>&1"
SetAcls: Info: WaitForSingleObject returned : 0x0
SetAcls: Info: Exit code for process : 0x534
SetAcls: Info: Leave.
SetAcls: Error: cannot set ACLs on etc folder: 0x534.
SetAcls: Error 0x80004005: Cannot set ACLs.
CustomAction SetAcls returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)
Action ended 18:26:24: InstallFinalize. Return value 3.
Action 18:26:24: Rollback. Rolling back action:
Rollback: SetAcls
Rollback: InstallSplunkService

You have to manually create local group "Administrators" with the same rights as german named group "Administratoren" to get the installer working.
It seems that the installer is not international 😉

Regards

Moritz

0 Karma

ChrisG
Splunk Employee
Splunk Employee

There are some upgrade defects in 6.2, particularly for non-English versions of Windows. See this previous Splunk Answers thread. The defects should be fixed in an upcoming maintenance release.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Note, this affects clean installs as well - not just upgrades.

Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...