Installation

Rollback Error during Splunk Enterprise installation on Windows server 2012 R2

Dinesh_Raja
Path Finder

Hello All,

I m trying to install Splunk 6.6.6 Windows 64 bit version on Windows 2012 R2 Server. But i am getting Rollback action screen and ended up with "Splunk Enterprise Setup Wizard ended prematurely" window.

I have gone through the similar issues on Splunk answers and couldn't find the resolution. I have Local Admin access for the respective server, There is enough space is in C: drive and also i can able to install Splunk universal forwarder 7.0.2 on same server without any issues.

Looking forward for your answers.

]1alt text

Labels (2)
0 Karma

skoomasteve
New Member

Something to try for anyone still experiencing this:
Go to local security policy--computer config--windows settings--security settings--user rights assignment and Check to make sure the AD account you're naming in the install wizard is not listed in "deny log on locally"

0 Karma

Dinesh_Raja
Path Finder

P.S : The issue was due to service account permissions.

0 Karma

dkcampbell
New Member

Can you provide more information about the specific service account permissions that were necessary to fix this?

0 Karma

Dinesh_Raja
Path Finder

P.S : I can able to install Splunk as 'Local System Account' , but unable to Install as 'Domain Account'. Could anyone suggest, what could be the issue?
Thanks.

0 Karma

p_gurav
Champion

Hi,

Can you try running below command before installing:

 msiexec /x splunk-<version>-x64.msi
0 Karma

Dinesh_Raja
Path Finder

@p_gurav, Thanks for suggestion.
I m getting "The installation package could not be opened. verify that the package exists" dialog box.

0 Karma

p_gurav
Champion

Run this command where you splunk .msi package is located

0 Karma

p_gurav
Champion
0 Karma

Dinesh_Raja
Path Finder

Hi @p_gurav,
The document mostly suggests about permissions only. I have local admin access, member of AD Domain.

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...