All Apps and Add-ons

Getting the following error when trying to start a forwarder on a linux system

nls7010
Path Finder

I am getting an error after loading Splunk forwarder on a Linux server (this same load is on other Linux servers with no issues): 6a257470b sp:7ffeb4a673a0 error:0 in liboneagentproc.so[7fd6a2560000+84000]
Aug 12 12:04:18 ladcivrnvpt03 kernel: traps: splunkd[66184] trap invalid opcode ip:7fd6a257470b sp:7ffeb4a673a0 error:0 in liboneagentproc.so[7fd6a2560000+84000]

I run the ./splunk start --accept-license and it appears to start, but if you ps -eaf | grep splunk, nothing is started.  No log files are generated in .../splunkforwarder/var/log/splunk for the splunkd process either.

Labels (1)
0 Karma

zulfikharnaiyar
Explorer

The compatibility issue exists between Dynatrace and Splunk 8.2. 

The below link describes it and the resolution as well - 

https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-oneagent/oneaget-troublesho...

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Invalid opcode can mean a few things.  Basically, the CPU saw an instruction it did not support and caused the kernel to trap and kill your splunkd process.  It died.

The message you pasted suggests the process death is related to liboneagentproc.so, which Google tells me is part of Dynatrace.  Does your machine have Dynatrace on it?  If it does, can you get rid of it to test and see if this fixes Splunk?

You may need to open a support case with both Dynatrace and Splunk and get them to work together on the issue.  I would probably start w/ Dynatrace because their library seems to be the one causing splunkd to crash.

 

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...