Splunk Enterprise

Upgrade Issue with Splunk Forwarder v10.0.0.0 on Windows 10 (32-bit)

Meta
New Member

Hello team,

We are currently testing the upgrade of Splunk Universal Forwarder (x86) version 10.0.0.0 on a Windows 10 32-bit virtual machine. However, the upgrade consistently fails with error code 1603

https://download.splunk.com/products/universalforwarder/releases/10.0.0/windows/splunkforwarder-10.0...

Please note the following observations:

  • Fresh installation of version 10.0.0.0 completes successfully.

  • Upgrade from version 9.4.2.0 to 9.4.3.0 works without any issues.

  • The upgrade was attempted both via UI and using silent switches, but the result was the same.

Unfortunately, we were unable to attach the log file for reference.

Meta_0-1753860096013.png

And actions are rolled back.

Meta_1-1753860167705.png

Could you please assist us in identifying and resolving the root cause of this issue?

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

To be fully honest, it's a "double donut" version.  I wouldn't be surprised if it was a bit buggy.

1. Don't just jump head-first into a version just because it's just been released. Unless there are fixes for issues hitting you or patches for known vulnerabilities, there's usually no reason to upgrade. Splunk can handle a wide range of older forwarders pretty well.

2. What you can do to help in product development and bug fixing is to gather the installation logs and raise a support ticket. (and - if the problem isn't internal to the installer but can be bypassed or it's triggered by some specific set of conditions - share the knowledge)

0 Karma

Meta
New Member

Hi @PickleRick 

Thank you for your response.

We are a third-party patch provider, similar to solutions like PatchMyPC or ManageEngine, offering automated patching services to our customers. As part of our process, we routinely test each new release to ensure compatibility and stability across supported environments.

For more details, please have a look at Autonomous Patching for Every Third-Party Windows App (adaptiva.com) (https://adaptiva.com/products/autonomous-patch)

 

Tags (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Meta 

According to the system requirements docs, Windows 10 does not support full Splunk Enterprise deployment, it only supports the Universal Forwarder. 

It is likely that your Windows 10 instance is missing key components/files which are required by Splunk which are only in the Windows Server varients.

Check out https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.0/plan-your-splunk-e... for more info on what is supported.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

0 Karma

Meta
New Member

Hi @livehybrid ,

Thank you for your response.

We are actually testing the Universal Forwarder only.

Also, just to clarify, the fresh installation is working fine on the Windows 10 VM. The issue occurs only during the upgrade process.

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...