Getting Data In

splunkd is not running

Exxnihiloo
Engager

I'm currently building my own home instance and I'm having some trouble with my UF.  

So far I've :

  1. installed the latest / correct version for my Ubuntu - Linux system
  2. sudo chown -RP splunk:splunk /opt/splunkforwarder/
  3. searched through SplunkForwarder.service to see if the correct user is applied (which it is)
  4. tried re-installing and running

 

./splunk enable boot-start​

as splunk user, and as root.

 

When using the splunk user, I have to authenticate as root anyway but i get the same results for both

 

./splunk start

 

results in "Done" after authentication

 

./splunk status

 

results in:

Warning: Attempting to revert the SPLUNK_HOME ownership

Warning: Executing "chown -R splunk:splunkfwd /opt/splunkforwarder"

Couldn't change ownership for /opt/splunkforwarder/etc : Operation not permitted

splunkd is not running.

 

./splunk enable boot-start

 

results in:

" A systemd unit file already exists at path ="/etc/systemd/system/SplunkForwarder.service". To add a Splunk generated systemd unit file, run 'splunk disable boot-start' before running this command. If there are custom settings that have been added to the unit file, create a backup copy first.

It seems no matter which account I use or which user has permissions, I'm unable to have access to any of the files under "/opt/splunkforwarder" nor am I able to start the UF itself or configure boot-start.

Labels (1)
0 Karma
1 Solution

renjith_nair
Legend

This seems to be a known issue with 9.1. As you can see a minimum privileged user splunkfwd is automatically created.

Reference : SPL-242093, SPL-242240 (https://docs.splunk.com/Documentation/Splunk/9.1.0/ReleaseNotes/KnownIssues)

Workaround - https://docs.splunk.com/Documentation/Forwarder/9.1.1/Forwarder/Installleastprivileged

 

 

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

This seems to be a known issue with 9.1. As you can see a minimum privileged user splunkfwd is automatically created.

Reference : SPL-242093, SPL-242240 (https://docs.splunk.com/Documentation/Splunk/9.1.0/ReleaseNotes/KnownIssues)

Workaround - https://docs.splunk.com/Documentation/Forwarder/9.1.1/Forwarder/Installleastprivileged

 

 

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

Exxnihiloo
Engager

Thanks for the help. Turns out I was using the "splunk:splunk" user and group instead of "splunkfwd". a clean install and correct addition of permissions helped

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...