Splunk Enterprise

Inability to install Splunk and complete setup

sylviee_o
New Member

Hello everyone, I use a Dell Windows laptop, and after downloading the Splunk enterprise 9.4.3 app for Windows, I'm unable to install it because of an error prompt. Please, can I get a step by step approach on fixing this?

IMG-20250624-WA0002.jpg

0 Karma

Prewin27
Contributor

@sylviee_o 

It appears you're upgrading from a much older version of Splunk to 9.4.x, which is causing the issue shown in your screenshot. To resolve this, you need to follow the supported upgrade path to ensure all components, including KV Store, are properly updated. Skipping intermediate versions can result in compatibility problems and failed upgrades.

Before upgrading to 9.4.x, verify that your KV Store server version is at least 4.2. If it isn't, first upgrade to an intermediate version (such as 9.3.x) that brings KV Store to the required level, then proceed to 9.4.x.
Also refer,
#https://docs.splunk.com/Documentation/Splunk/9.4.2/Admin/MigrateKVstore

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

sylviee_o
New Member

Thank you for tour response. I installed the 9.4.2 version, but I am still getting the same error message as I shared earlier. Is there a step-by-step way to identify if the MSI log file is missing? I don't know what else to do or how to solve this problem. Thank you

0 Karma

Prewin27
Contributor

@sylviee_o 

It appears there may be remnants from previous Splunk installations, and I’m assuming you’re running Windows.
Please follow the steps below to ensure you completely remove any old Splunk
 
-Open Services (services.msc), find Splunk and stop it
-Go to Control Panel → Programs → Programs and Features ->Find Splunk and uninstall
-Manually delete the Splunk installation directory (eg:  C:\Program Files\Splunk)
-Clean Up the Windows Registry also,
Open regedit and search for any remaining keys related to Splunk under and delete it
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\
      HKEY_LOCAL_MACHINE\SOFTWARE\
 
Reboot your machine and try again with the latest Splunk Enterprise installation file.
 
 
 
Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
 
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. Is it a fresh installation or an upgrade?

2. You have the immediate debugging steps on screen.

0 Karma

sylviee_o
New Member

It is a fresh installation, and updating the previous version doesn't help either as I am getting same message.

The debugging steps aren't clear to me, and the steps I have taken based on the instructions are not yielding any positive result for me.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. If by "fresh" you mean "I had Splunk before on this machine but uninstalled it", this doesn't count as completely fresh as some data from the old installation might have been left. The error suggests some old KVstore contens lying around.

If this is supposed to be a fresh install, I'd go for cleaning the computer completely from all leftovers - most importantly delete (or move away) old director C:\Program Files\Splunk. You could also remove old Splunk user and comb through the registry whether anything pertaining to Splunk was left.

After that I'd rerun the installer with logging - see https://docs.splunk.com/Documentation/Splunk/9.4.2/Installation/InstallonWindowsviathecommandline#In...

 

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...