Security

Splunk Enterprise upgrade to 9.4.0 failing - failing to set permissions

MMershon
Explorer

Hello,

 

Attempting to upgrade our test environment from 9.3.2 to 9.4.0 on Windows Server 2019 fails with the following message found in splunk.log:

<time>
C:\windows\system32\cmd.exe /c "C:\Windows\system32\icacls "C:\Program Files\Splunk" /grant "LocalSystem:(OI)(CI)(F)" /T /C >> "<out to %temp%\splunk.log>" 2>&1"


LocalSystem: No mapping between account names and security IDs was done.
Successfully processed 0 files;  Failed processing 1 files.

Seems pretty straightforward. Attempting to grant Full Access/Control to all files and subdirectories...
EXCEPT...

It almost certainly should be "NT AUTHORITY\System", not "LocalSystem".
Pretty sure this is just a Linux vs Windows nomenclature thing.

Are there any suggestions for forcing to permission as the correct account or do I need to open a support ticket to have this fixed in the next release?

dudhatjanhavi
Explorer

We are running into a similar issue, were you able to figure out what happened?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...