Splunk Enterprise

Upgrade Issue with Splunk Forwarder v10.0.0.0 on Windows 10 (32-bit)

Meta
New Member

Hello team,

We are currently testing the upgrade of Splunk Universal Forwarder (x86) version 10.0.0.0 on a Windows 10 32-bit virtual machine. However, the upgrade consistently fails with error code 1603

https://download.splunk.com/products/universalforwarder/releases/10.0.0/windows/splunkforwarder-10.0...

Please note the following observations:

  • Fresh installation of version 10.0.0.0 completes successfully.

  • Upgrade from version 9.4.2.0 to 9.4.3.0 works without any issues.

  • The upgrade was attempted both via UI and using silent switches, but the result was the same.

Unfortunately, we were unable to attach the log file for reference.

Meta_0-1753860096013.png

And actions are rolled back.

Meta_1-1753860167705.png

Could you please assist us in identifying and resolving the root cause of this issue?

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

To be fully honest, it's a "double donut" version.  I wouldn't be surprised if it was a bit buggy.

1. Don't just jump head-first into a version just because it's just been released. Unless there are fixes for issues hitting you or patches for known vulnerabilities, there's usually no reason to upgrade. Splunk can handle a wide range of older forwarders pretty well.

2. What you can do to help in product development and bug fixing is to gather the installation logs and raise a support ticket. (and - if the problem isn't internal to the installer but can be bypassed or it's triggered by some specific set of conditions - share the knowledge)

0 Karma

livehybrid
Ultra Champion

Hi @Meta 

According to the system requirements docs, Windows 10 does not support full Splunk Enterprise deployment, it only supports the Universal Forwarder. 

It is likely that your Windows 10 instance is missing key components/files which are required by Splunk which are only in the Windows Server varients.

Check out https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.0/plan-your-splunk-e... for more info on what is supported.

:glowing_star: Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

0 Karma

Meta
New Member

Hi @livehybrid ,

Thank you for your response.

We are actually testing the Universal Forwarder only.

Also, just to clarify, the fresh installation is working fine on the Windows 10 VM. The issue occurs only during the upgrade process.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...