Getting Data In

Universal Forwarder

drggfish1
Explorer

I am getting a mismatch between the version of OPENSSL installed on my OS and in the Universal Forwarder. It seems to be keeping me from running the Universal Forwarder as a systemd process.

NAME="AlmaLinux"
VERSION="10.1 (Heliotrope Lion)"

[splunk@ip-172-31-34-212 bin]$ openssl version
OpenSSL 3.5.1 1 Jul 2025 (Library: OpenSSL 3.5.1 1 Jul 2025)

systemctl: /opt/splunkforwarder/lib/libcrypto.so.3: version `OPENSSL_3.4.0' not found (required by /usr/lib64/systemd/libsystemd-shared-257-13.el10.alma.1.so)

Thanks

 

Labels (1)
0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust

Hi @drggfish1 

Pls check this post:

https://splunk.my.site.com/customer/s/article/OPENSSL-3-4-0-not-found-warning-message-after-splunk-e...

 

Karma points appreciated, if this solves your issue, pls consider accepting it as solution, thanks..

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

kml_uvce
Builder

Rename/remove Splunk's OpenSSL libraries

cd /opt/splunkforwarder/lib
sudo mv libcrypto.so.3 libcrypto.so.3.bak
sudo mv libssl.so.3 libssl.so.3.bak

 

Then try starting the forwarder again:

sudo systemctl start SplunkForwarder

kamal singh bisht
0 Karma

PickleRick
SplunkTrust
SplunkTrust

That will effectively cripple, if not completely break, the UF since it will have no openssl libraries to use.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

openssl version shows which version is found by your shell.

Try bin/splunk cmd openssl version to find which version splunk is using.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @drggfish1 

Pls check this post:

https://splunk.my.site.com/customer/s/article/OPENSSL-3-4-0-not-found-warning-message-after-splunk-e...

 

Karma points appreciated, if this solves your issue, pls consider accepting it as solution, thanks..

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

PickleRick
SplunkTrust
SplunkTrust

We had a similar question not long ago...

What _exactly_ are you doing? UF ships with own openssl version which should be used within UF and only within UF. So systemctl trying to use openssl seems either like a bug or you are doing something wrong way.

Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...