Deployment Architecture

Splunk & Linux Kernel 3.0

dshakespeare_sp
Splunk Employee
Splunk Employee

Can Splunk run with Splunk on Linux 3.0/3.1 kernel. The documentation just states 2.6+ but there is nothing explicit Linux 3.0/3.1

Tags (1)

jonuwz
Influencer

It runs just fine on suse SLES 11 sp2 which has a 3.x kernel. Been running it 24x7 for months with no problem.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

I would expect the kernel version to largely not matter to Splunk as long as it is relatively modern - that is supports things like NPTL (New POSIX Thread Library) which was a kernel 2.4 feature. The kernel maintainers go to a substantial effort to make sure that no kernel changes break existing user-mode code, and Splunk does not have anything that runs outside of userspace. Sometimes though, the maintainers do mess up and a substantial flap1 comes of it.

But, now be warned of the difference between 'runs' and 'is supported'. If there is a problem, it will be up to Splunk support to decide if they want to commit to supporting these newer kernels at this time.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...