Installation

windows MSI upgrade fails, with installer unable to create the service

yannK
Splunk Employee
Splunk Employee

While upgrading on windows server, with the MSI installer, the splunkd service creation may fail with "Create Splunk services: Splunk Installer was unable to create Splunk Services"
and a popup " "splunk installer was unable to launch splunk's first time run error code: 1"

The error is also visible on the msi logs in %TEMP%\Splunk-(version).log


*** _LaunchAppEx: Create process executing: cmd.exe /c ""C:\Program Files\Splunk\bin\splunk.exe" enable boot-start-loop --answer-yes --no-prompt --accept-license >> C:\Users\btester\AppData\Local\Temp\Splunk-108.5.18156.log 2>>&1"
*** _LaunchAppEx: WaitForSingleObject retval=0, exitCode=1
*** Create Splunk services: Splunk Installer was unable to create Splunk Services.

Tags (2)
1 Solution

yannK
Splunk Employee
Splunk Employee

It can be a permission issue or a problem with the service.

The workaround is to remove the service before upgrading :

  • make sure to stop splunk, check the service list
  • double check the name of the service (should be splunkd)
  • delete the service on the command line : sc delete splunkd
  • apply the installer as admininstrator

View solution in original post

yannK
Splunk Employee
Splunk Employee

It can be a permission issue or a problem with the service.

The workaround is to remove the service before upgrading :

  • make sure to stop splunk, check the service list
  • double check the name of the service (should be splunkd)
  • delete the service on the command line : sc delete splunkd
  • apply the installer as admininstrator
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...