Installation

Difficulty on installing Splunk UF 8.2.4 on Server 2019

rajyah
Communicator

Hi everyone,

 

I'm currently having a difficulty installing a UF in one of our Microsoft Server 2019 that is residing as VM via Hyper-V.

Please do take note that this is a fresh installation of universal forwarder in this machine. Also, this server is acting as a domain controller and we would like to get its logs.

 

Kindly show me the way since I have been searching for hours and could not find a proper answer for this. Also, I would like to avoid doing a reformatting on this specific machine just to install the UF. Thank you.

 

This shows the logs:

 

12:23:30 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splunkdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:34 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splknetdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:37 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultInstall 128 C:\Program Files\SplunkUniversalForwarder\bin\SplunkMonitorNoHandleDrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:40 AM
C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal first-time-run --answer-yes --no-prompt >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"

This appears to be your first time running this version of Splunk.
12:23:40 AM
C:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
The certificate generation script did not generate the expected certificate file:C:\Program Files\SplunkUniversalForwarder\etc\auth\server.pem. Splunkd port communication will not work.
SSL certificate generation failed.
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\i18n
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\appserver\modules\static\css
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\upload
		Creating: C:\Program Files\SplunkUniversalForwarder\var\run\splunk\search_telemetry
		Creating: C:\Program Files\SplunkUniversalForwarder\var\spool\splunk
		Creating: C:\Program Files\SplunkUniversalForwarder\var\spool\dirmoncache
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\authDb
		Creating: C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\hashDb
12:23:45 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\SplunkMonitorNoHandleDrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:47 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splknetdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"
12:23:49 AM
C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe  setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\SplunkUniversalForwarder\bin\splunkdrv.inf >> "C:\Users\ADMINI~1\AppData\Local\Temp\splunk.log" 2>&1"

 

 

Labels (3)
0 Karma

jho-splunk
Splunk Employee
Splunk Employee

Hi @rajyah,

I'm afraid we'll need a Process Monitor log to troubleshoot this further, but unfortunately they're too big to attach here so I'd suggest opening a case with Splunk Support.

Cheers,

 

 - Jo.

 

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...