Security

Splunk Enterprise upgrade to 9.4.0 failing - failing to set permissions

MMershon
Explorer

Hello,

 

Attempting to upgrade our test environment from 9.3.2 to 9.4.0 on Windows Server 2019 fails with the following message found in splunk.log:

<time>
C:\windows\system32\cmd.exe /c "C:\Windows\system32\icacls "C:\Program Files\Splunk" /grant "LocalSystem:(OI)(CI)(F)" /T /C >> "<out to %temp%\splunk.log>" 2>&1"


LocalSystem: No mapping between account names and security IDs was done.
Successfully processed 0 files;  Failed processing 1 files.

Seems pretty straightforward. Attempting to grant Full Access/Control to all files and subdirectories...
EXCEPT...

It almost certainly should be "NT AUTHORITY\System", not "LocalSystem".
Pretty sure this is just a Linux vs Windows nomenclature thing.

Are there any suggestions for forcing to permission as the correct account or do I need to open a support ticket to have this fixed in the next release?

dudhatjanhavi
Explorer

We are running into a similar issue, were you able to figure out what happened?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...