ok, did just that and here is a section from the install log where things go south and setup begins rolling back MSI (s) (FC:F4) [12:47:17:625]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIF1EF.tmp, Entrypoint: StopSplunkServiceDefCA MSI (s) (FC:68) [12:47:17:625]: Generating random cookie. MSI (s) (FC:68) [12:47:17:625]: Created Custom Action Server with PID 2452 (0x994). MSI (s) (FC:70) [12:47:17:719]: Running as a service. MSI (s) (FC:70) [12:47:17:719]: Hello, I'm your 64bit Elevated Non-remapped custom action server. StopSplunkServiceDef: Warning: Invalid property ignored: FailCA=. StopSplunkServiceDef: Info: Properties: splunkHome: C:\Program Files\Splunk, svcName: Splunkd. StopSplunkServiceDef: Info: Enter. StopSplunkServiceDef: Info: service Splunkd already exists StopSplunkServiceDef: Info: Leave. MSI (s) (FC:F4) [12:47:17:734]: Executing op: ActionStart(Name=ReinstallRegmonDrv,,) Action 12:47:17: ReinstallRegmonDrv. MSI (s) (FC:F4) [12:47:17:734]: Executing op: CustomActionSchedule(Action=ReinstallRegmonDrv,ActionType=1281,Source=BinaryData,Target=InstallRegmonDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=) MSI (s) (FC:F4) [12:47:17:750]: Executing op: ActionStart(Name=UninstallNetmonDrv,,) Action 12:47:17: UninstallNetmonDrv. MSI (s) (FC:F4) [12:47:17:750]: Executing op: CustomActionSchedule(Action=UninstallNetmonDrv,ActionType=3073,Source=BinaryData,Target=UninstallNetmonDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=) MSI (s) (FC:14) [12:47:17:812]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIF2AB.tmp, Entrypoint: UninstallNetmonDrvCA UninstallNetmonDrv: Warning: Invalid property ignored: FailCA=. UninstallNetmonDrv: Info: Driver inf file: C:\Program Files\Splunk\bin\splknetdrv.inf. UninstallNetmonDrv: Info: Enter. UninstallNetmonDrv: Info: Service: splknetdrv, state: 1. UninstallNetmonDrv: Info: splknetdrv service does not exists. UninstallNetmonDrv: Info: Enter. Args: rundll32.exe, setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\splknetdrv.inf UninstallNetmonDrv: Info: SystemPath is: C:\Windows\system32\ UninstallNetmonDrv: Info: Execute string: C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\splknetdrv.inf >> "C:\Users\MUSZYN~1\AppData\Local\Temp\splunk.log" 2>&1" UninstallNetmonDrv: Info: WaitForSingleObject returned : 0x0 UninstallNetmonDrv: Info: Exit code for process : 0x0 UninstallNetmonDrv: Info: Leave. MSI (s) (FC:F4) [12:47:18:390]: Executing op: ActionStart(Name=ReinstallNohandleDrv,,) Action 12:47:18: ReinstallNohandleDrv. MSI (s) (FC:F4) [12:47:18:390]: Executing op: CustomActionSchedule(Action=ReinstallNohandleDrv,ActionType=1281,Source=BinaryData,Target=InstallNohandleDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=) MSI (s) (FC:F4) [12:47:18:390]: Executing op: ActionStart(Name=UninstallRegmonDrv,,) Action 12:47:18: UninstallRegmonDrv. MSI (s) (FC:F4) [12:47:18:406]: Executing op: CustomActionSchedule(Action=UninstallRegmonDrv,ActionType=3073,Source=BinaryData,Target=UninstallRegmonDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=) MSI (s) (FC:50) [12:47:18:453]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIF53D.tmp, Entrypoint: UninstallRegmonDrvCA UninstallRegmonDrv: Warning: Invalid property ignored: FailCA=. UninstallRegmonDrv: Info: Driver inf file: C:\Program Files\Splunk\bin\splunkdrv.inf. UninstallRegmonDrv: Info: Enter. UninstallRegmonDrv: Info: Service: splunkdrv, state: 1. UninstallRegmonDrv: Info: splunkdrv service does not exists. UninstallRegmonDrv: Info: Enter. Args: rundll32.exe, setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\splunkdrv.inf UninstallRegmonDrv: Info: SystemPath is: C:\Windows\system32\ UninstallRegmonDrv: Info: Execute string: C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\splunkdrv.inf >> "C:\Users\MUSZYN~1\AppData\Local\Temp\splunk.log" 2>&1" UninstallRegmonDrv: Info: WaitForSingleObject returned : 0x0 UninstallRegmonDrv: Info: Exit code for process : 0x0 UninstallRegmonDrv: Info: Leave. MSI (s) (FC:F4) [12:47:19:031]: Executing op: ActionStart(Name=ReinstallNetmonDrv,,) Action 12:47:19: ReinstallNetmonDrv. MSI (s) (FC:F4) [12:47:19:047]: Executing op: CustomActionSchedule(Action=ReinstallNetmonDrv,ActionType=1281,Source=BinaryData,Target=InstallNetmonDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=) MSI (s) (FC:F4) [12:47:19:047]: Executing op: ActionStart(Name=UninstallNohandleDrv,,) Action 12:47:19: UninstallNohandleDrv. MSI (s) (FC:F4) [12:47:19:047]: Executing op: CustomActionSchedule(Action=UninstallNohandleDrv,ActionType=3073,Source=BinaryData,Target=UninstallNohandleDrvCA,CustomActionData=SystemFolder=C:\Windows\SysWOW64\;System64Folder=C:\Windows\system32\;SplunkHome=C:\Program Files\Splunk\;FailCA=) MSI (s) (FC:88) [12:47:19:094]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIF7BE.tmp, Entrypoint: UninstallNohandleDrvCA UninstallNohandleDrv: Warning: Invalid property ignored: FailCA=. UninstallNohandleDrv: Info: Driver inf file: C:\Program Files\Splunk\bin\SplunkMonitorNoHandleDrv.inf. UninstallNohandleDrv: Info: Enter. UninstallNohandleDrv: Info: Service: SplunkMonitorNoHandle, state: 1. UninstallNohandleDrv: Info: SplunkMonitorNoHandle service does not exists. UninstallNohandleDrv: Info: Enter. Args: rundll32.exe, setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\SplunkMonitorNoHandleDrv.inf UninstallNohandleDrv: Info: SystemPath is: C:\Windows\system32\ UninstallNohandleDrv: Info: Execute string: C:\Windows\system32\cmd.exe /c "C:\Windows\system32\rundll32.exe setupapi,InstallHinfSection DefaultUninstall 128 C:\Program Files\Splunk\bin\SplunkMonitorNoHandleDrv.inf >> "C:\Users\MUSZYN~1\AppData\Local\Temp\splunk.log" 2>&1" UninstallNohandleDrv: Info: WaitForSingleObject returned : 0x0 UninstallNohandleDrv: Info: Exit code for process : 0x0 UninstallNohandleDrv: Info: Leave. MSI (s) (FC:F4) [12:47:19:703]: Executing op: ActionStart(Name=RemoveFiles,Description=Removing files,Template=File: [1], Directory: [9]) Action 12:47:19: RemoveFiles. Removing files MSI (s) (FC:F4) [12:47:19:703]: Executing op: ProgressTotal(Total=17609,Type=1,ByteEquivalent=175000) MSI (s) (FC:F4) [12:47:19:703]: Executing op: SetTargetFolder(Folder=C:\ProgramData\Splunk Enterprise\)
... View more