Deployment Architecture

Splunk & Linux Kernel 3.0

dshakespeare_sp
Splunk Employee
Splunk Employee

Can Splunk run with Splunk on Linux 3.0/3.1 kernel. The documentation just states 2.6+ but there is nothing explicit Linux 3.0/3.1

Tags (1)

jonuwz
Influencer

It runs just fine on suse SLES 11 sp2 which has a 3.x kernel. Been running it 24x7 for months with no problem.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

I would expect the kernel version to largely not matter to Splunk as long as it is relatively modern - that is supports things like NPTL (New POSIX Thread Library) which was a kernel 2.4 feature. The kernel maintainers go to a substantial effort to make sure that no kernel changes break existing user-mode code, and Splunk does not have anything that runs outside of userspace. Sometimes though, the maintainers do mess up and a substantial flap1 comes of it.

But, now be warned of the difference between 'runs' and 'is supported'. If there is a problem, it will be up to Splunk support to decide if they want to commit to supporting these newer kernels at this time.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...