You will be prompted for a password for the Splunk admin user.
If you want to change any of these default installation settings, click Customize Options and proceed with the instructions in "Customize Options" in this topic.
When you choose to install with the default settings, the installer does the following: The Windows installer gives you two choices: Install with the default installation settings, or configure all settings prior to installing.
To work around this problem, if you know that the instance will be a member of a search head or indexer cluster, consider installing the software into a directory with a short path length, for example C:\Splunk or D:\SPL. There is no way to change this configuration. Windows cannot address a file path that is longer than this, and if Splunk software creates a file with a path length that is longer than MAX_PATH, it cannot retrieve the file later. The Windows API has a path limitation of MAX_PATH which Microsoft defines as 260 characters including the drive letter, colon, backslash, 256-characters for the path, and a null terminating character. You must configure such software to avoid on-access scanning of Splunk Enterprise installation directories and processes before you start a Splunk installation.Ĭonsider installing Splunk software into a directory with a short path nameīy default, the Splunk MSI file installs the software to \Program Files\Splunk on the system drive (the drive that booted your Windows machine.) While this directory is fine for many Splunk software installations, it might be problematic for installations that run in distributed deployments or that employ advanced Splunk features such as search-head or indexer clustering.
Any software with a device driver that intermediates between Splunk Enterprise and the operating system can restrict processing power available to Splunk Enterprise, causing slowness and even an unresponsive system. The Splunk Enterprise indexing subsystem requires high disk throughput. The user you choose has ramifications on what you must do prior to installing the software, and more details can be found there.ĭisable or limit antivirus software if able
If you plan to upgrade Splunk Enterprise, see How to upgrade Splunk Enterprise for instructions and migration considerations before proceeding.īefore you install Choose the Windows user Splunk should run asīefore installing, see Choose the Windows user Splunk should run as to determine which user account Splunk should run as to address your specific needs. The universal forwarder is a separate executable from Splunk Enterprise and uses a different installer.
Note: If, rather than installing Splunk Enterprise, you want to install the Splunk universal forwarder, see Install a Windows universal forwarder from an installer in the Universal Forwarder manual. If you attempt to run the installer in such a way, it warns you and prevents the installation. For example, you cannot install Splunk Enterprise on a machine that runs Windows Server 2003. You also cannot install Splunk Enterprise on a machine that runs an unsupported OS. You cannot install or run the 32-bit version of Splunk Enterprise for Windows on a 64-bit Windows machine. See Install on Windows from the command line for the command line installation procedure. More options, such as silent installation, are available if you install from the command line. You can install Splunk Enterprise on Windows with the Graphical User Interface (GUI)-based installer or from the command line.