Getting Data In

When trying to Install a Splunk forwarder on Linux, why am I getting the following error: 'splunk: command not found'

jeffsuchomel
Engager

I am trying to install the Splunk forwarder (for Splunk Cloud) on an Ubuntu 16.04 server using the instructions on the following:

https://docs.splunk.com/Documentation/SplunkCloud/7.2.3/User/ForwardDataToSplunkCloudFromLinux

Everything seems to go well until I get to Step 3: Download and install the universal forwarder credentials. When I type in the command to install the .spl file, I keep getting the 'splunk: command not found' error message.

Does anybody know why I this is happening?

0 Karma
1 Solution

jeffsuchomel
Engager

Please disregard. I think I found the answer to my question after more digging. The doc states to issue the command 'splunk install app -auth :' to install the forwarder credentials.

I found that I needed to enter the command './splunk......' instead.

View solution in original post

0 Karma

tarunchawla28
Engager

If you don't want to write './splunk' and use 'splunk' instead, execute this in your bin directory ->
source setSplunkEnv

You will get this as output->
Tab-completion of "splunk " is available.

Now, you can use 'splunk'.

0 Karma

jeffsuchomel
Engager

Please disregard. I think I found the answer to my question after more digging. The doc states to issue the command 'splunk install app -auth :' to install the forwarder credentials.

I found that I needed to enter the command './splunk......' instead.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...