Getting Data In

Universal Forwarder

drggfish1
Engager

I am getting a mismatch between the version of OPENSSL installed on my OS and in the Universal Forwarder. It seems to be keeping me from running the Universal Forwarder as a systemd process.

NAME="AlmaLinux"
VERSION="10.1 (Heliotrope Lion)"

[splunk@ip-172-31-34-212 bin]$ openssl version
OpenSSL 3.5.1 1 Jul 2025 (Library: OpenSSL 3.5.1 1 Jul 2025)

systemctl: /opt/splunkforwarder/lib/libcrypto.so.3: version `OPENSSL_3.4.0' not found (required by /usr/lib64/systemd/libsystemd-shared-257-13.el10.alma.1.so)

Thanks

 

Labels (1)
0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust

Hi @drggfish1 

Pls check this post:

https://splunk.my.site.com/customer/s/article/OPENSSL-3-4-0-not-found-warning-message-after-splunk-e...

 

Karma points appreciated, if this solves your issue, pls consider accepting it as solution, thanks..

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

kml_uvce
Builder

Rename/remove Splunk's OpenSSL libraries

cd /opt/splunkforwarder/lib
sudo mv libcrypto.so.3 libcrypto.so.3.bak
sudo mv libssl.so.3 libssl.so.3.bak

 

Then try starting the forwarder again:

sudo systemctl start SplunkForwarder

kamal singh bisht
0 Karma

PickleRick
SplunkTrust
SplunkTrust

That will effectively cripple, if not completely break, the UF since it will have no openssl libraries to use.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

openssl version shows which version is found by your shell.

Try bin/splunk cmd openssl version to find which version splunk is using.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @drggfish1 

Pls check this post:

https://splunk.my.site.com/customer/s/article/OPENSSL-3-4-0-not-found-warning-message-after-splunk-e...

 

Karma points appreciated, if this solves your issue, pls consider accepting it as solution, thanks..

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

PickleRick
SplunkTrust
SplunkTrust

We had a similar question not long ago...

What _exactly_ are you doing? UF ships with own openssl version which should be used within UF and only within UF. So systemctl trying to use openssl seems either like a bug or you are doing something wrong way.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...