Installation

Difficulty on installing Splunk UF 8.2.4 on Server 2019

rajyah
Communicator

Hi everyone,

 

I'm currently having a difficulty installing a UF in one of our Microsoft Server 2019 that is residing as VM via Hyper-V.

Please do take note that this is a fresh installation of universal forwarder in this machine. Also, this server is acting as a domain controller and we would like to get its logs.

 

Kindly show me the way since I have been searching for hours and could not find a proper answer for this. Also, I would like to avoid doing a reformatting on this specific machine just to install the UF. Thank you.

 

This shows the logs:

 

12:23:30 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splunkdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:34 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splknetdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:37 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\SplunkMonitorNoHandleDrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:40 AM
C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal first-time-run --answer-yes --no-prompt >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"

This appears to be your first time running this version of Splunk.
12:23:40 AM
C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
The certificate generation script did not generate the expected certificate file:C:\Program Files\SplunkUniversalForwarder\etc\auth\server.pem. Splunkd port communication will not work.
SSL certificate generation failed.
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\i18n
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\modules\static\css
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\upload
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\search_telemetry
		Creating: C:\Program Files\SplunkUniversalForwarder\var\spool\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\spool\dirmoncache
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\authDb
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\hashDb
12:23:45 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\SplunkMonitorNoHandleDrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:47 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splknetdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:49 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splunkdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"

 

 

Labels (3)
0 Karma

jho-splunk
Splunk Employee
Splunk Employee

Hi @rajyah,

I'm afraid we'll need a Process Monitor log to troubleshoot this further, but unfortunately they're too big to attach here so I'd suggest opening a case with Splunk Support.

Cheers,

 

 - Jo.

 

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...