Hello team,
We are currently testing the upgrade of Splunk Universal Forwarder (x86) version 10.0.0.0 on a Windows 10 32-bit virtual machine. However, the upgrade consistently fails with error code 1603.
Please note the following observations:
Fresh installation of version 10.0.0.0 completes successfully.
Upgrade from version 9.4.2.0 to 9.4.3.0 works without any issues.
The upgrade was attempted both via UI and using silent switches, but the result was the same.
Unfortunately, we were unable to attach the log file for reference.
And actions are rolled back.
Could you please assist us in identifying and resolving the root cause of this issue?
To be fully honest, it's a "double donut" version. I wouldn't be surprised if it was a bit buggy.
1. Don't just jump head-first into a version just because it's just been released. Unless there are fixes for issues hitting you or patches for known vulnerabilities, there's usually no reason to upgrade. Splunk can handle a wide range of older forwarders pretty well.
2. What you can do to help in product development and bug fixing is to gather the installation logs and raise a support ticket. (and - if the problem isn't internal to the installer but can be bypassed or it's triggered by some specific set of conditions - share the knowledge)
Hi @PickleRick
Thank you for your response.
We are a third-party patch provider, similar to solutions like PatchMyPC or ManageEngine, offering automated patching services to our customers. As part of our process, we routinely test each new release to ensure compatibility and stability across supported environments.
For more details, please have a look at Autonomous Patching for Every Third-Party Windows App (adaptiva.com) (https://adaptiva.com/products/autonomous-patch)
Hi @Meta
According to the system requirements docs, Windows 10 does not support full Splunk Enterprise deployment, it only supports the Universal Forwarder.
It is likely that your Windows 10 instance is missing key components/files which are required by Splunk which are only in the Windows Server varients.
Check out https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.0/plan-your-splunk-e... for more info on what is supported.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Hi @livehybrid ,
Thank you for your response.
We are actually testing the Universal Forwarder only.
Also, just to clarify, the fresh installation is working fine on the Windows 10 VM. The issue occurs only during the upgrade process.