Installation

Rollback Error during Splunk Enterprise installation on Windows server 2012 R2

Dinesh_Raja
Path Finder

Hello All,

I m trying to install Splunk 6.6.6 Windows 64 bit version on Windows 2012 R2 Server. But i am getting Rollback action screen and ended up with "Splunk Enterprise Setup Wizard ended prematurely" window.

I have gone through the similar issues on Splunk answers and couldn't find the resolution. I have Local Admin access for the respective server, There is enough space is in C: drive and also i can able to install Splunk universal forwarder 7.0.2 on same server without any issues.

Looking forward for your answers.

]1alt text

Labels (2)
0 Karma

skoomasteve
New Member

Something to try for anyone still experiencing this:
Go to local security policy--computer config--windows settings--security settings--user rights assignment and Check to make sure the AD account you're naming in the install wizard is not listed in "deny log on locally"

0 Karma

Dinesh_Raja
Path Finder

P.S : The issue was due to service account permissions.

0 Karma

dkcampbell
New Member

Can you provide more information about the specific service account permissions that were necessary to fix this?

0 Karma

Dinesh_Raja
Path Finder

P.S : I can able to install Splunk as 'Local System Account' , but unable to Install as 'Domain Account'. Could anyone suggest, what could be the issue?
Thanks.

0 Karma

p_gurav
Champion

Hi,

Can you try running below command before installing:

 msiexec /x splunk-<version>-x64.msi
0 Karma

Dinesh_Raja
Path Finder

@p_gurav, Thanks for suggestion.
I m getting "The installation package could not be opened. verify that the package exists" dialog box.

0 Karma

p_gurav
Champion

Run this command where you splunk .msi package is located

0 Karma

p_gurav
Champion
0 Karma

Dinesh_Raja
Path Finder

Hi @p_gurav,
The document mostly suggests about permissions only. I have local admin access, member of AD Domain.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...