Hi together,
I want to update an old Splunk environment on Windows Server 2016 Standard. The update fails and the error log (%TEMP%/splunk.log) looks like this:
C:\Windows\system32\cmd.exe /c ""C:\Program Files\Splunk\bin\splunk.exe" enable boot-start-loop --answer-yes --no-prompt --accept-license >> "C:\Users\Admin\AppData\Local\Temp\splunk.log" 2>&1"
Service Splunkd install error (CreateService): The specified service already exists.
Installing service Splunkd
Error running "splunkd install": error 1
C:\Windows\system32\cmd.exe /c ""C:\Program Files\Splunk\bin\splunk.exe" start --answer-yes --no-prompt --accept-license --auto-ports >> "C:\Users\Admin\AppData\Local\Temp\splunk.log" 2>&1"
Splunk> Now with more code!
Checking prerequisites...
Checking http port [8443]: open
Checking mgmt port [8089]: open
Checking appserver port []: open
Checking kvstore port [8191]: open
Checking configuration... Done.
Checking critical directories... Done
Checking indexes...
Validated: _audit _internal _introspection _metrics _telemetry _thefishbucket cim_modactions history main summary synology westermo wineventlog
Invalid key in stanza [install] in C:\Program Files\Splunk\etc\apps\dnslookup\default\app.conf, line 10: author (value: Travis Freeland).
Invalid key in stanza [install] in C:\Program Files\Splunk\etc\apps\dnslookup\default\app.conf, line 11: description (value: dnslookup <forward|reverse> <input field> <outputfield>, servicelookup <input field> <output field> <optional services file path>).
Invalid key in stanza [settings] in C:\Program Files\Splunk\etc\system\local\web.conf, line 365: engine.autoreload_on (value: False).
Invalid key in stanza [framework] in C:\Program Files\Splunk\etc\system\local\web.conf, line 493: django_enable (value: True).
Invalid key in stanza [framework] in C:\Program Files\Splunk\etc\system\local\web.conf, line 496: django_path (value: etc/apps/framework).
Invalid key in stanza [framework] in C:\Program Files\Splunk\etc\system\local\web.conf, line 499: django_force_enable (value: False).
Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'
Checking filesystem compatibility... Done
Checking conf files for problems...
Checking default conf files for edits...
Validating installed files against hashes from 'C:\Program Files\Splunk\splunk-8.0.0-1357bef0a7f6-windows-64-manifest'
Error initializing openssl -- cannot compute checksums.
Error encountered while attempting to validate files
Problems were found, please review your files and move customizations to local
All preliminary checks passed.
Starting splunk server daemon (splunkd)...
Splunkd: Starting (pid 2636)
For me it looks like openssl does not work properly and is cancelling the update, but I'm not sure about it. Do you have any ideas on what the problem is and what I need to do to make the update work?
Hi @lukrator,
This is an unusual error—I have not encountered it before. To troubleshoot further, I think that we may need to get a Procmon log. Are you able to open a ticket with Support?
- Jo.