<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to start splunk first time in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/588993#M8747</link>
    <description>&lt;P&gt;For others who may encounter this problem in the future. You will see this error on RHEL 8 and derivatives if you are using the tar.gz installation and fapolicyd is enabled and you have not whitelisted the splunk installation directory&lt;/P&gt;&lt;P&gt;To confirm whether fapolicyd is preventing you from running splunk you can use the following audit log search command&lt;/P&gt;&lt;LI-CODE lang="c"&gt;sudo ausearch --start today -m fanotify -i&lt;/LI-CODE&gt;&lt;P&gt;you will see output like this:&lt;/P&gt;&lt;LI-CODE lang="c"&gt;node=rhel8.example.com type=PROCTITLE msg=audit(03/14/2022 17:43:30.150:21294716) : proctitle=/opt/splunk/bin/splunk start
node=rhel8.example.com type=PATH msg=audit(03/14/2022 17:43:30.150:21294716) : item=0 name=/opt/splunk/bin/python3.7 inode=4328145 dev=fd:03 mode=file,555 ouid=splunk ogid=splunk rdev=00:00 obj=unconfined_u:object_r:usr_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0
node=rhel8.example.com type=CWD msg=audit(03/14/2022 17:43:30.150:21294716) : cwd=/home/lamech
node=rhel8.example.com type=SYSCALL msg=audit(03/14/2022 17:43:30.150:21294716) : arch=x86_64 syscall=execve success=no exit=EPERM(Operation not permitted) a0=0x5604c24f1980 a1=0x7ffeb0c870d0 a2=0x7ffeb0c86f40 a3=0x5 items=1 ppid=228305 pid=228318 auid=lamech uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=splunk exe=/opt/splunk/bin/splunk subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null)
node=rhel8.example.com type=FANOTIFY msg=audit(03/14/2022 17:43:30.150:21294716) : resp=deny
&lt;/LI-CODE&gt;</description>
    <pubDate>Mon, 14 Mar 2022 23:32:37 GMT</pubDate>
    <dc:creator>Lamech</dc:creator>
    <dc:date>2022-03-14T23:32:37Z</dc:date>
    <item>
      <title>Why is there an error when trying to start Splunk first time?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574548#M8582</link>
      <description>&lt;P&gt;We tried to install splunk 8.1.0 and after untarring the file tried to start splunk both as root and splunk user via /opt/splunk/bin/splunk start&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error comes up as execve: Operation not permitted while running command /opt/splunk/bin/splunkd&lt;/P&gt;
&lt;P&gt;Any urgent help is appreciated&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 17:40:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574548#M8582</guid>
      <dc:creator>sombhtr239</dc:creator>
      <dc:date>2022-06-06T17:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk first time</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574579#M8583</link>
      <description>&lt;P&gt;When Splunk is run as root, a number of files are written with root as the owner.&amp;nbsp; Trying to run Splunk as a different user will fail until those files are given to the different user.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;chown -r splunk:splunk /opt/splunk&lt;/LI-CODE&gt;&lt;P&gt;You may have to use systemctl to start splunk.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;sudo systemctl start splunk&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 11 Nov 2021 13:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574579#M8583</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-11T13:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk first time</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574585#M8584</link>
      <description>&lt;P&gt;Tried steps already, its still not working. We tried the following to no go:&lt;/P&gt;&lt;P&gt;1) Tried to start splunk as splunk user did not go&lt;/P&gt;&lt;P&gt;2) Kept filesystem with Splunk and tried to start splunk with root did not work.&lt;/P&gt;&lt;P&gt;3) Tried to enable systemctl did not work.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 14:34:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574585#M8584</guid>
      <dc:creator>sombhtr239</dc:creator>
      <dc:date>2021-11-11T14:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk first time</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574624#M8585</link>
      <description>&lt;P&gt;If you just did the install, any reason why you didn't use 8.2.3?&lt;/P&gt;&lt;P&gt;I know you say you have tried as splunk, does that mean you created the account and then did su - splunk?&lt;/P&gt;&lt;P&gt;Show the output of&lt;/P&gt;&lt;PRE&gt; ls -ld /opt/splunk&lt;/PRE&gt;&lt;P&gt;and&lt;/P&gt;&lt;PRE&gt;ls -l /opt/splunk&lt;/PRE&gt;&lt;P&gt;After you have tried, show the output of&lt;/P&gt;&lt;PRE&gt;tail -30 /var/log/messages &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 16:45:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574624#M8585</guid>
      <dc:creator>Jamie</dc:creator>
      <dc:date>2021-11-11T16:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk first time</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574700#M8586</link>
      <description>&lt;P&gt;We are trying to scale up our environment and the other 2 SH peer are running on SE8.0.5, hence tried both 8.0.5 and 8.1.0.&amp;nbsp; Will check /var/log/messages; however already changed permission for /opt/splunk . Tried to run via systemctl as well to No go as of now.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 07:49:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574700#M8586</guid>
      <dc:creator>sombhtr239</dc:creator>
      <dc:date>2021-11-12T07:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk first time</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574904#M8591</link>
      <description>&lt;P&gt;I found this issue more with the server. Every time we reboot the server, it failed to turn on. Finally created a new VM which resolve the problem. Thanks all for your contribution. Issue resolved now.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 11:09:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/574904#M8591</guid>
      <dc:creator>sombhtr239</dc:creator>
      <dc:date>2021-11-15T11:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk first time</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/588993#M8747</link>
      <description>&lt;P&gt;For others who may encounter this problem in the future. You will see this error on RHEL 8 and derivatives if you are using the tar.gz installation and fapolicyd is enabled and you have not whitelisted the splunk installation directory&lt;/P&gt;&lt;P&gt;To confirm whether fapolicyd is preventing you from running splunk you can use the following audit log search command&lt;/P&gt;&lt;LI-CODE lang="c"&gt;sudo ausearch --start today -m fanotify -i&lt;/LI-CODE&gt;&lt;P&gt;you will see output like this:&lt;/P&gt;&lt;LI-CODE lang="c"&gt;node=rhel8.example.com type=PROCTITLE msg=audit(03/14/2022 17:43:30.150:21294716) : proctitle=/opt/splunk/bin/splunk start
node=rhel8.example.com type=PATH msg=audit(03/14/2022 17:43:30.150:21294716) : item=0 name=/opt/splunk/bin/python3.7 inode=4328145 dev=fd:03 mode=file,555 ouid=splunk ogid=splunk rdev=00:00 obj=unconfined_u:object_r:usr_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0
node=rhel8.example.com type=CWD msg=audit(03/14/2022 17:43:30.150:21294716) : cwd=/home/lamech
node=rhel8.example.com type=SYSCALL msg=audit(03/14/2022 17:43:30.150:21294716) : arch=x86_64 syscall=execve success=no exit=EPERM(Operation not permitted) a0=0x5604c24f1980 a1=0x7ffeb0c870d0 a2=0x7ffeb0c86f40 a3=0x5 items=1 ppid=228305 pid=228318 auid=lamech uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=splunk exe=/opt/splunk/bin/splunk subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null)
node=rhel8.example.com type=FANOTIFY msg=audit(03/14/2022 17:43:30.150:21294716) : resp=deny
&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 14 Mar 2022 23:32:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/588993#M8747</guid>
      <dc:creator>Lamech</dc:creator>
      <dc:date>2022-03-14T23:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk first time</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/600730#M8844</link>
      <description>&lt;P&gt;I just ran into this same issue.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To whitelist the application ran the following:&lt;/P&gt;&lt;P&gt;fapolicyd-cli --file add /opt/splunk&lt;/P&gt;&lt;P&gt;fapolicyd-cli --update&lt;/P&gt;&lt;P&gt;systemctl restart fapolicyd&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 17:25:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-is-there-an-error-when-trying-to-start-Splunk-first-time/m-p/600730#M8844</guid>
      <dc:creator>xNGreenex</dc:creator>
      <dc:date>2022-06-06T17:25:01Z</dc:date>
    </item>
  </channel>
</rss>

