Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Windows Installer installed the product. Product Name: program_name. Product Version: program_version. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 1603.
|English: Request a translation of the event description in plain English.|
As per T735566, this is a normal, informational event, recording the installation of a program. However, only if the status code is 0 the installation is actually successful. Any other code would indicate that the installation encountered a problem. For example, Error code 1603 means "Fatal error during installation.", denoting a problem that could not be fixed by the installer itself.
Each problem would obviously be specific to the actual installation package (the .msi file) so there is specific solution for all 1033 events. If possible, the MsiInstaller verbose logging should be enabled in order to get more details about the installation failure. Also, there might be other events with more specific information about the problem.
Ideally, the software vendor should be contacted about the problem. In one situation, the vendor of a specific software explained that the installation failed due to an incompatibility with the software already installed.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated