All Apps and Add-ons

VCSA (6.7): Impossible to add splunk universal forwarder at startup

gordanristic
New Member

Hi all,

I have an issue with startup script generated by this command:
"/opt/splunk/bin/splunk enable boot-start"
Result is:
"service splunk does not support chkconfig"

Script generated start with this:

!/bin/sh

/etc/init.d/splunk

init script for Splunk.

generated by 'splunk enable boot-start'.

chkconfig: 2345 90 60

description: Splunk indexer service

...
Launching "chkconfig --add splunk" return the same value ("service splunk does not support chkconfig").
Modifying "# chkconfig: 2345 90 60" to "# chkconfig: 2345 20 80" does not change anything.

VSCA is running on Photon Linux 1.0 (Build 62c543d).
Additionnal info: when I start splunk with /etc/init.d/splunk start it works perfectly
Universal forwarder version is 7.3.1

Any suggestions?

Thank you!

0 Karma
1 Solution

Masa
Splunk Employee
Splunk Employee

/opt/splunk/bin/splunk enable boot-start calls splunk and splunk create an init script.
That script does not include chkconfig lines. That's why you get the error.

More important concern is that the linux distribution is not a supported OS. So, I think you should avoid installing a UF on VSCA directly. Instead, can you send logs to syslog server, and install Splunk UF on the syslog server to monitor the syslog log files?

View solution in original post

0 Karma

Masa
Splunk Employee
Splunk Employee

/opt/splunk/bin/splunk enable boot-start calls splunk and splunk create an init script.
That script does not include chkconfig lines. That's why you get the error.

More important concern is that the linux distribution is not a supported OS. So, I think you should avoid installing a UF on VSCA directly. Instead, can you send logs to syslog server, and install Splunk UF on the syslog server to monitor the syslog log files?

0 Karma

gordanristic
New Member

Hi Masa,

I will try that way, I just followed the official documentation (Forward VMware vCenter Linux appliance logs to Splunk Enterprise)

I'll give you a feedback.

Thank you for your answer.

0 Karma

gordanristic
New Member

Hi again Masa,

It seems to be enough to make it work. I don't understand why the official documentation is not up to date as the App is not free (minimum a 5 GB per month of additionnal Splunk Enterprise licence).

Thank you for your help Masa.

0 Karma

Masa
Splunk Employee
Splunk Employee

Hi, @gordanristic

Good to hear that it was enough to make it work.

Regarding the official doc you're referring, can you post the URL link in this thread?
Just F.Y.I., the app download page explains that it comes with a 60-day trial license(ref: https://splunkbase.splunk.com/app/725/#/overview)

0 Karma

gordanristic
New Member

Hi @Masa

Here is the url: https://docs.splunk.com/Documentation/VMW/3.4.5/Installation/CollectVMwarevCenterServerLinuxApplianc...

For the licensing part, I already asked to a Splunk partner in my country the pricing: for small infrastructure it is really expansive.

0 Karma

Masa
Splunk Employee
Splunk Employee

Hi, @gordanristic,
Sounds like you were good regarding the question above.

The url sounds like UF can be installed in the appliance. In that case, you may file a Splunk Support case to ask more detail if you would like to know more detail of supporting UF installation in the VSCA appliance. But, they may tell you the limitation like what I answered here.

Hope this helps.

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...