Getting Data In

Installing Splunk Universal Forwarder on Oracle Linux is having issue

dharshini
Explorer

Hi All,

I have setup Oracle Linux on my VM to collect logs using Universal forwarder. UF not able to start service with error

" bash: ./splunk cannot execute binary file".

I did try using all the available linux versions for the forwarder installation, still the same error.
UF version: 7.2.3 (64bit)
OS: Oracle Linux 6.9 (64bit)

Help point out if I am missing anything important.

Thanks.

0 Karma

mzasoc
Loves-to-Learn Lots

May I know the link where I can download splunk universal forwarded  for Oracle Linux?

Tags (1)
0 Karma

deepashri_123
Motivator

Hey@dharshini,

You can try referring this answer:
https://answers.splunk.com/answers/101245/cannot-execute-binary-file-linux-virtual-machine.html

Let me know if this helps!!

0 Karma

dharshini
Explorer

Thanks for the help. I did check the previous answer and executed file ./splunk command to check if it was 64 bit and verified yes.

0 Karma

harsmarvania57
Ultra Champion

Hi,

Which command are you using to start splunk ? It should be like this $SPLUNK_HOME/bin/splunk start where $SPLUNK_HOME is your splunk installation directory

0 Karma

dharshini
Explorer

Yes. I have installed on /opt folder and started using this command,

cd /opt/splunkforwarder/bin
./splunk start --accept-license

0 Karma

harsmarvania57
Ultra Champion

Can you please check whether you have downloaded correct version of Splunk Forwarder. You can check splunk executable whether it is 32-bit or 64-bit using command file $SPLUNK_HOME/bin/splunk and also check your OS version using uname -a both must be 64-bit (I know you have provided this info in your question but just double checking)

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...