Installation

Rollback Error during Splunk Enterprise installation on Windows server 2012 R2

Dinesh_Raja
Path Finder

Hello All,

I m trying to install Splunk 6.6.6 Windows 64 bit version on Windows 2012 R2 Server. But i am getting Rollback action screen and ended up with "Splunk Enterprise Setup Wizard ended prematurely" window.

I have gone through the similar issues on Splunk answers and couldn't find the resolution. I have Local Admin access for the respective server, There is enough space is in C: drive and also i can able to install Splunk universal forwarder 7.0.2 on same server without any issues.

Looking forward for your answers.

]1alt text

Labels (2)
0 Karma

skoomasteve
New Member

Something to try for anyone still experiencing this:
Go to local security policy--computer config--windows settings--security settings--user rights assignment and Check to make sure the AD account you're naming in the install wizard is not listed in "deny log on locally"

0 Karma

Dinesh_Raja
Path Finder

P.S : The issue was due to service account permissions.

0 Karma

dkcampbell
New Member

Can you provide more information about the specific service account permissions that were necessary to fix this?

0 Karma

Dinesh_Raja
Path Finder

P.S : I can able to install Splunk as 'Local System Account' , but unable to Install as 'Domain Account'. Could anyone suggest, what could be the issue?
Thanks.

0 Karma

p_gurav
Champion

Hi,

Can you try running below command before installing:

 msiexec /x splunk-<version>-x64.msi
0 Karma

Dinesh_Raja
Path Finder

@p_gurav, Thanks for suggestion.
I m getting "The installation package could not be opened. verify that the package exists" dialog box.

0 Karma

p_gurav
Champion

Run this command where you splunk .msi package is located

0 Karma

p_gurav
Champion
0 Karma

Dinesh_Raja
Path Finder

Hi @p_gurav,
The document mostly suggests about permissions only. I have local admin access, member of AD Domain.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...