Installation

Error loading logging conf file - can't start Splunk Enterprise Server

rdjoraev_splunk
Splunk Employee
Splunk Employee

Not able to start Splunk.

When running "./splunk start" from the command line, Splunk Enterprise Server fails to start with the following error message:

Error loading logging conf file='/opt/splunk/etc/log.cfg'; runContext=splunkd

Tags (2)
1 Solution

rdjoraev_splunk
Splunk Employee
Splunk Employee

As per error message, root cause of the issue is related to log.cfg file in located the /opt/splunk/etc/ directory.

Checked in the splunkd.log file in $SPLUNK_HOME/var/log/splunk and observed the following message in it:

WARN Logger - /opt/splunk/etc/log.cfg:11: Parse error at "TailingProcessork....

It was found that the category.TailingProcessor parameter name was not spelled correctly. After updating the parameter name in the log.cfg file, user was able to start Splunk Server successfully.

View solution in original post

rdjoraev_splunk
Splunk Employee
Splunk Employee

As per error message, root cause of the issue is related to log.cfg file in located the /opt/splunk/etc/ directory.

Checked in the splunkd.log file in $SPLUNK_HOME/var/log/splunk and observed the following message in it:

WARN Logger - /opt/splunk/etc/log.cfg:11: Parse error at "TailingProcessork....

It was found that the category.TailingProcessor parameter name was not spelled correctly. After updating the parameter name in the log.cfg file, user was able to start Splunk Server successfully.

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...