<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk on ARM Achitecture in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/754143#M23214</link>
    <description>&lt;P&gt;The ARM package is available however not publicly visible you have to request access to&amp;nbsp;&lt;BR /&gt;&lt;A href="https://voc.splunk.com/preview/cmp-graviton-early-access" target="_blank"&gt;https://voc.splunk.com/preview/cmp-graviton-early-access&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Oct 2025 18:02:17 GMT</pubDate>
    <dc:creator>rainmk</dc:creator>
    <dc:date>2025-10-09T18:02:17Z</dc:date>
    <item>
      <title>Splunk on ARM Achitecture</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/512005#M2930</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am new to SPlunk and I have the following CPU Architecture running Debian Buster 10:&lt;/P&gt;&lt;P&gt;processor : 0&lt;BR /&gt;model name : ARMv7 Processor rev 10 (v7l)&lt;BR /&gt;BogoMIPS : 6.00&lt;BR /&gt;Features : half thumb fastmult vfp edsp neon vfpv3 tls vfpd32&lt;BR /&gt;CPU implementer : 0x41&lt;BR /&gt;CPU architecture: 7&lt;BR /&gt;CPU variant : 0x2&lt;BR /&gt;CPU part : 0xc09&lt;BR /&gt;CPU revision : 10&lt;/P&gt;&lt;P&gt;Can splunk enterprise will be able run on this system or do I have to use splunk forwarder only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2020 04:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/512005#M2930</guid>
      <dc:creator>tcha9078</dc:creator>
      <dc:date>2020-08-01T04:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk on ARM Achitecture</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/512011#M2931</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;based on this&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements&lt;/A&gt;&amp;nbsp;ARM is only supported as UF.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2020 08:50:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/512011#M2931</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-01T08:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk on ARM Achitecture</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/512049#M2934</link>
      <description>&lt;P&gt;Wait patiently and it may come &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.linkedin.com/feed/update/urn:li:activity:6691303981484011520/" target="_blank"&gt;https://www.linkedin.com/feed/update/urn:li:activity:6691303981484011520/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/2012"&gt;@MuS&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2020 12:15:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/512049#M2934</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2020-08-02T12:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk on ARM Achitecture</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/512051#M2935</link>
      <description>&lt;P&gt;Especially after Apple has changed to ARM processors later on this year...&lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2020 13:55:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/512051#M2935</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-02T13:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk on ARM Achitecture</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/529419#M4155</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;as mentioned before, only the UF is available for ARMv6 (no support).&lt;/P&gt;&lt;P&gt;Starting with V8.1 there is a fully supported ARMv8 UF available:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Try this as of November, 14th, 2020:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=ARM&amp;amp;platform=linux&amp;amp;version=8.1.0&amp;amp;product=universalforwarder&amp;amp;filename=splunkforwarder-8.1.0-f57c09e87251-Linux-armv8.tgz&amp;amp;wget=true" target="_blank"&gt;https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=ARM&amp;amp;platform=linux&amp;amp;version=8.1.0&amp;amp;product=universalforwarder&amp;amp;filename=splunkforwarder-8.1.0-f57c09e87251-Linux-armv8.tgz&amp;amp;wget=true&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you run on Raspberry Pi you might need to install an Ubuntu (or other ARMv8, 64bit) distro because the original Raspbian Linux (Buster) is based on ARMv7 (32 bit).&lt;/P&gt;&lt;P&gt;A full Splunk Enterprise installation is not supported/available currently but if it's for your home environment you might search for QEMU and Splunk Enterprise...&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please mark one of the answers as valid.&lt;/P&gt;&lt;P&gt;Happy splunking,&lt;/P&gt;&lt;P&gt;Holger&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Nov 2020 17:49:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/529419#M4155</guid>
      <dc:creator>hsesterhenn_spl</dc:creator>
      <dc:date>2020-11-14T17:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk on ARM Achitecture</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/650297#M16812</link>
      <description>&lt;P&gt;For those using Linux on Arm, you can run Splunk on a x86 container using docker:&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;DOCKER_DEFAULT_PLATFORM=linux/amd64 docker run --privileged -d -p 8000:8000 -e "SPLUNK_START_ARGS=--accept-license" -e "SPLUNK_PASSWORD=&amp;lt;password&amp;gt;" --name splunk splunk/splunk:latest&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 21:21:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/650297#M16812</guid>
      <dc:creator>maat</dc:creator>
      <dc:date>2023-07-12T21:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk on ARM Achitecture</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/754143#M23214</link>
      <description>&lt;P&gt;The ARM package is available however not publicly visible you have to request access to&amp;nbsp;&lt;BR /&gt;&lt;A href="https://voc.splunk.com/preview/cmp-graviton-early-access" target="_blank"&gt;https://voc.splunk.com/preview/cmp-graviton-early-access&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 18:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/754143#M23214</guid>
      <dc:creator>rainmk</dc:creator>
      <dc:date>2025-10-09T18:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk on ARM Achitecture</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/755293#M23436</link>
      <description>&lt;P&gt;Thanks this was helpful, but it did not fully solve it for me. For anyone else that ends up here, the full solution was as follows:&lt;/P&gt;&lt;P&gt;Test environment: Ubuntu Server 24.04 ARM64 &amp;nbsp;running in a VM on Macbook M3&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;Install docker&lt;/STRONG&gt;&lt;/H3&gt;&lt;PRE&gt;sudo apt install docker.io&lt;BR /&gt;&lt;BR /&gt;sudo systemctl enable docker&lt;BR /&gt;&lt;BR /&gt;sudo systemctl start docker&lt;/PRE&gt;&lt;H3&gt;&lt;STRONG&gt;Pull Splunk Docker Image&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;Have to add &lt;STRONG&gt;&lt;EM&gt;--platform&lt;/EM&gt; &lt;/STRONG&gt;option to specify the pull should be done for amd64 architecture.&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;sudo docker pull --platform=linux/amd64 splunk/splunk:latest&lt;/PRE&gt;&lt;H3&gt;&lt;STRONG&gt;Install QEMU&amp;nbsp;&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;Need to install QEMU so docker can use emulation when running amd64 splunk on arm64 linux host. I took this from docker official documentation here:&amp;nbsp;&lt;A href="https://docs.docker.com/build/building/multi-platform/" target="_blank" rel="noopener"&gt;https://docs.docker.com/build/building/multi-platform/&lt;/A&gt; in section about installing QEMU manually.&lt;/P&gt;&lt;PRE&gt;sudo docker run --privileged --rm tonistiigi/binfmt --install all&lt;/PRE&gt;&lt;H3&gt;&lt;STRONG&gt;Run Splunk Docker Image&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;Adding &lt;STRONG&gt;&lt;EM&gt;--platform&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;is not necessary here, but it avoids a warning&lt;/P&gt;&lt;P&gt;Even though it is not mentioned in the official Splunk documentation (&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/9.3/install-splunk-enterprise-in-virtual-and-containerized-environments/deploy-and-run-splunk-enterprise-inside-a-docker-container" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/9.3/install-splunk-enterprise-in-virtual-and-containerized-environments/deploy-and-run-splunk-enterprise-inside-a-docker-container&lt;/A&gt;) I had to add&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;-e SPLUNK_GENERAL_TERMS=--accept-sgt-current-at-splunk-com&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;because I was getting an error when splunk was starting up. I found the error in the docker logs and it specifically said to add this. Maybe its a new requirement in latest version of splunk.&lt;/P&gt;&lt;PRE&gt;sudo docker run -d --platform=linux/amd64 -p 8000:8000 -e SPLUNK_GENERAL_TERMS=--accept-sgt-current-at-splunk-com -e SPLUNK_START_ARGS='--accept-license' -e SPLUNK_PASSWORD='&amp;lt;insert_password&amp;gt;' --name splunk-enterprise splunk/splunk:latest&lt;/PRE&gt;&lt;P&gt;Note: I initially added &lt;STRONG&gt;&lt;EM&gt;--privileged&lt;/EM&gt;&lt;/STRONG&gt; option to above command, but it caused an error in deployment of docker image which was related to app armour and the loaded unix_chkpwd profile which is specific to ubuntu 24.04. The issue was confirmed to be app armor related because running &lt;EM&gt;&lt;STRONG&gt;sudo aa-complain unix_chkpwd &amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;command caused the error to just turn into a warning and then the docker container started correctly. For some reason, if you do not add &lt;STRONG&gt;&lt;EM&gt;--privileged&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; option then this issue is non-existent and so far splunk seems to be running fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 06:50:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/755293#M23436</guid>
      <dc:creator>jmel0</dc:creator>
      <dc:date>2025-11-07T06:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk on ARM Achitecture</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/757402#M23723</link>
      <description>&lt;P class=""&gt;Your steps were spot on and they did get me to the Enterprise dashboard login page, but I’m still unable to actually log in to my instance. I’ve tried:&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;P class=""&gt;Resetting the admin password from the CLI.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Re‑using the initial password I set during installation.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Resetting the password again via the “Manage password” prompt in the UI.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any thoughts on what to check for next?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jan 2026 06:51:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-on-ARM-Achitecture/m-p/757402#M23723</guid>
      <dc:creator>vigmanutd931</dc:creator>
      <dc:date>2026-01-17T06:51:32Z</dc:date>
    </item>
  </channel>
</rss>

