This may have already been posted but I couldn't find it and I burnt up about 2-3 hours scratching my head...
After a service restart, if you get the following error message:
"Windows could not start the Splunkd service on Local Computer. Error 2: The system cannot find the file specified."
Answer can be found below. I hope it helps someone save some time.
Windows key + r Type regedit HKLM > System > CurrentControlSet > services > Splunkd (or SplunkForwarder) If ImagePath has quotes in it, delete them and start the service.
Windows key + r Type regedit HKLM > System > CurrentControlSet > services > Splunkd (or SplunkForwarder) If ImagePath has quotes in it, delete them and start the service.
This didn't work for me either and I also receive:
Error 1067: The process terminated unexpectedly.
The answer did not work when I tried it
What do you do when DoD IA policies flag this as a possible security violation and require the quotes?