- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
macOS Sierra 10.12 kills Splunk
Quite surprised no one reported this. I can't run Splunk anymore even fresh install on macOS Sierra.
Probably Splunk should alert users/engineers not to upgrade macOS before it's fixed.
Checking indexes...
homePath='/Users/philip/Projects/splunk_demo2/var/lib/splunk/audit/db' of index=_audit on unusable filesystem.
Validating databases (splunkd validatedb) failed with code '1'. If you cannot resolve the issue(s) above after consulting documentation, please file a case online at http://www.splunk.com/page/submit_issue
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


There is information--and warnings--about this in the documentation now: Splunk Enterprise does not start due to unusable file system.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi Folks,
I did this but I still get the following error message. I suspect I'm doing something really, really dumb. If you could point me in the right direction, that would be great.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


You need to tell your macOS firewall to allow connections to :8000. When you first launch Splunk Enterprise you should have been presented with a dialogue box asking to allow or deny access.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

The System Requirements page does not list MacOS 10.12 Sierra as a supported operating system for Splunk Enterprise at this time.
You are welcome to install it on that version of MacOS but you do so solely at your own risk. Overriding file system lock check is not the best look.
We will advise on the page I linked when support for MacOS 10.12 is available and supported.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Got answer from Splunk guy. We can add following line to $SPLUNK_HOME/etc/splunk-launch.conf
OPTIMISTIC_ABOUT_FILE_LOCKING = 1
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How should I add line to $SPLUNK_HOME/etc/splunk-launch.conf? I have no idea where I can find this conf file.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

If the file doesn't exist, you simply need to create it and place the above line in it.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hmmm. I am surprised to hear about a deployment where that file doesn't exist. Is this merely a scenario of $SPLUNK_HOME
not already defined? Did you change that to where Splunk is installed (like /opt/splunk/
)?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Works on macOS High Sierra 10.13 (17A405)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

If you are concerned about your data in any way then you should not not not do this. This variable basically drops all filesystem lock checks and any data you store might or might not be retrievable.
There is no support yet for MacOS 10.12. We're working on it, and when it's ready, we'll make sure everybody knows.
If you are doing this as a test, then go right ahead, but you assume all risk for your data otherwise.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Malmoore,
Does Splunk now have support for apple 10.12 unified logs ?
Please, advise.
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

You should click Accept
on your answer.
