<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk 10: Journald input not working with debian 13 (trixie) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/759897#M120391</link>
    <description>&lt;P&gt;You missed libssl.so.&amp;nbsp; My solution is&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;chmod 0000 /opt/splunkforwarder/lib/libcrypto.so* /opt/splunkforwarder/lib/libssl.so*&lt;/PRE&gt;</description>
    <pubDate>Thu, 02 Apr 2026 22:08:22 GMT</pubDate>
    <dc:creator>tsteiner38</dc:creator>
    <dc:date>2026-04-02T22:08:22Z</dc:date>
    <item>
      <title>Splunk 10: Journald input not working with debian 13 (trixie)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/753649#M119648</link>
      <description>&lt;P&gt;After upgrading to Debian 13&amp;nbsp;Journald input is not working anymore with Splunk 10.x.&lt;/P&gt;&lt;P&gt;This error I found in the internal logs:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ERROR ExecProcessor [3095663 ExecProcessor] - message from "/opt/splunk/bin/splunkd journald-modinput '$@'" journalctl: /opt/splunk/lib/libcrypto.so.3: version `OPENSSL_3.4.0' not found (required by /usr/lib/x86_64-linux-gnu/systemd/libsystemd-shared-257.so)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(With Debian 12&amp;nbsp;Journald input is working. And with Splunk 9.4.x&amp;nbsp;Journald input is working with Debian 13)&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 12:21:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/753649#M119648</guid>
      <dc:creator>Beerman</dc:creator>
      <dc:date>2025-09-26T12:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 10: Journald input not working with debian 13 (trixie)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/753650#M119649</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/250484"&gt;@Beerman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Debian 13 isnt listed as a supported OS for Splunk Enterprise at&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.0/plan-your-splunk-enterprise-installation/system-requirements-for-use-of-splunk-enterprise-on-premises" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.0/plan-your-splunk-enterprise-installation/system-requirements-for-use-of-splunk-enterprise-on-premises&lt;/A&gt;&amp;nbsp;so it could be that there is some incompatibility here with newer versions of OpenSSL.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Despite it not being referenced as a supported OS it might be worth raising a support request/case at&amp;nbsp;&lt;A href="https://splunk.com/support" target="_blank"&gt;https://splunk.com/support&lt;/A&gt;&amp;nbsp;so that it could potentially be addressed for a future minor release.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you? If so, please consider&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 12:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/753650#M119649</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-09-26T12:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 10: Journald input not working with debian 13 (trixie)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/753673#M119651</link>
      <description>&lt;P&gt;As &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt; said, Debian 13 isn’t listed as a supported OS for Splunk Enterprise 10.0, so this incompatibility with newer OpenSSL versions could be the cause of the issue.&lt;/P&gt;&lt;P&gt;It’s recommended to raise a support request at &lt;A href="https://splunk.com/support" target="_blank" rel="noopener noreferrer"&gt;https://splunk.com/support&lt;/A&gt; so Splunk can address it in a future minor release.&lt;/P&gt;&lt;P&gt;If this helps, some karma would be appreciated!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 18:23:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/753673#M119651</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2025-09-26T18:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 10: Journald input not working with debian 13 (trixie)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/756106#M119935</link>
      <description>&lt;P class="lia-align-justify"&gt;Getting the same issue with AlmaLinux 9.7...&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Tried this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;sudo mv /opt/splunk/lib/libcrypto.so.3 /opt/splunk/lib/libcrypto.so.3.bak
sudo ln -s /usr/lib64/libcrypto.so.3 /opt/splunk/lib/libcrypto.so.3&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;but then I get this instead:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Traceback (most recent call last):
  File "/opt/splunk/lib/python3.9/site-packages/splunk/clilib/cli.py", line 25, in &amp;lt;module&amp;gt;
    import splunk.clilib.control_api as ca
  File "/opt/splunk/lib/python3.9/site-packages/splunk/clilib/control_api.py", line 5, in &amp;lt;module&amp;gt;
    import splunk.clilib._internal as _internal
  File "/opt/splunk/lib/python3.9/site-packages/splunk/clilib/_internal.py", line 7, in &amp;lt;module&amp;gt;
    from splunk.clilib import manage_search
  File "/opt/splunk/lib/python3.9/site-packages/splunk/clilib/manage_search.py", line 16, in &amp;lt;module&amp;gt;
    from splunk.clilib import bundle_paths
  File "/opt/splunk/lib/python3.9/site-packages/splunk/clilib/bundle_paths.py", line 24, in &amp;lt;module&amp;gt;
    import ssl
  File "/opt/splunk/lib/python3.9/ssl.py", line 99, in &amp;lt;module&amp;gt;
    import _ssl             # if we can't import it, let the error propagate
ImportError: /opt/splunk/lib/python3.9/lib-dynload/_ssl.cpython-39-x86_64-linux-gnu.openssl3.so: undefined symbol: RAND_egd, version OPENSSL_3.0.0&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 02 Dec 2025 18:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/756106#M119935</guid>
      <dc:creator>eplacido</dc:creator>
      <dc:date>2025-12-02T18:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 10: Journald input not working with debian 13 (trixie)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/759897#M120391</link>
      <description>&lt;P&gt;You missed libssl.so.&amp;nbsp; My solution is&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;chmod 0000 /opt/splunkforwarder/lib/libcrypto.so* /opt/splunkforwarder/lib/libssl.so*&lt;/PRE&gt;</description>
      <pubDate>Thu, 02 Apr 2026 22:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-10-Journald-input-not-working-with-debian-13-trixie/m-p/759897#M120391</guid>
      <dc:creator>tsteiner38</dc:creator>
      <dc:date>2026-04-02T22:08:22Z</dc:date>
    </item>
  </channel>
</rss>

