Deployment Architecture

Splunk Universal Forwarder 7.x setup ended prematurely on Windows Server 2012 R2 Datacenter edition

kutlusensoy
New Member

Hi everyone,

I've read lots of articles for that issue, but I can't find any solutions.

Here is the premature splunk-utility.log content

2-13-2019 11:56:48.198 +0300 INFO  ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
02-13-2019 11:56:48.198 +0300 INFO  ServerConfig - Host name option is "".
02-13-2019 11:56:49.983 +0300 INFO  loader - Running utility: "check-transforms-keys"
02-13-2019 11:56:49.983 +0300 INFO  loader - Getting configuration data from: c:\Program Files\SplunkUniversalForwarder\etc\myinstall\splunkd.xml
02-13-2019 11:56:49.983 +0300 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to c:\Program Files\SplunkUniversalForwarder\etc\modules
02-13-2019 11:56:49.983 +0300 INFO  loader - loading modules from c:\Program Files\SplunkUniversalForwarder\etc\modules
02-13-2019 11:56:49.999 +0300 INFO  loader - Writing out composite configuration file: c:\Program Files\SplunkUniversalForwarder\var\run\splunk\composite.xml

And also, I can read that Setup Failed because of Error code 1603 from log files in C:\TMP

Do you have any suggestion to solve this problem.

Thanks.

0 Karma

ddrillic
Ultra Champion

How does the splunkd.log end?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...