Deployment Architecture

Splunk & Linux Kernel 3.0

dshakespeare_sp
Splunk Employee
Splunk Employee

Can Splunk run with Splunk on Linux 3.0/3.1 kernel. The documentation just states 2.6+ but there is nothing explicit Linux 3.0/3.1

Tags (1)

jonuwz
Influencer

It runs just fine on suse SLES 11 sp2 which has a 3.x kernel. Been running it 24x7 for months with no problem.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

I would expect the kernel version to largely not matter to Splunk as long as it is relatively modern - that is supports things like NPTL (New POSIX Thread Library) which was a kernel 2.4 feature. The kernel maintainers go to a substantial effort to make sure that no kernel changes break existing user-mode code, and Splunk does not have anything that runs outside of userspace. Sometimes though, the maintainers do mess up and a substantial flap1 comes of it.

But, now be warned of the difference between 'runs' and 'is supported'. If there is a problem, it will be up to Splunk support to decide if they want to commit to supporting these newer kernels at this time.

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...