IT Operations Discussions
All the up-time. All the nines.

Oracle Linux 8 splunkforwarder install failing. Operation not permitted

ntamcv
Observer

I have automated scripts working fine with CentOS 7/8 without issue.

When attempting the same installation on OL8 

with cmd line:

$ /opt/splunkforwarder/bin/splunk start --answer-yes --no-prompt --accept-license --seed-passwd #######

I get the following:

ouldn't run "/opt/splunkforwarder/bin/splunkd" "btool": Operation not permitted
couldn't run "/opt/splunkforwarder/bin/splunkd" "btool": Operation not permitted
couldn't run "/opt/splunkforwarder/bin/splunkd" "btool": Operation not permitted
Did not find "disabled" setting of "kvstore" stanza in server bundle.

Splunk> Map. Reduce. Recycle.

Checking prerequisites...
couldn't run "/opt/splunkforwarder/bin/splunkd" "btool": Operation not permitted
Checking mgmt port [8089]: couldn't run "/opt/splunkforwarder/bin/splunkd" "btool": Operation not permitted
open
execve: Operation not permitted
while running command /opt/splunkforwarder/bin/splunkd
Checking kvstore port [8191]: couldn't run "/opt/splunkforwarder/bin/splunkd" "btool": Operation not permitted
open
couldn't run "/opt/splunkforwarder/bin/splunkd" "btool": Operation not permitted
execve: Operation not permitted
while running command /opt/splunkforwarder/bin/splunkd

 

 

- checked permissions on folder, set owner to root:root

- selinux disabled

- no other security software present

 

0 Karma

ntamcv
Observer

cat /etc/os-release
NAME="Oracle Linux Server"
VERSION="8.3"
ID="ol"
ID_LIKE="fedora"
VARIANT="Server"
VARIANT_ID="server"
VERSION_ID="8.3"
PLATFORM_ID="platform:el8"
PRETTY_NAME="Oracle Linux Server 8.3"
ANSI_COLOR="0;31"
CPE_NAME="cpe:/o:oracle:linux:8:3:server"
HOME_URL="https://linux.oracle.com/"
BUG_REPORT_URL="https://bugzilla.oracle.com/"

ORACLE_BUGZILLA_PRODUCT="Oracle Linux 8"
ORACLE_BUGZILLA_PRODUCT_VERSION=8.3
ORACLE_SUPPORT_PRODUCT="Oracle Linux"
ORACLE_SUPPORT_PRODUCT_VERSION=8.3
$uname -a
Linux ####### 4.18.0-240.10.1.el8_3.x86_64 #1 SMP Mon Jan 4 12:04:12 PST 2021 x86_64 x86_64 x86_64 GNU/Linux

Forwarder version is 8.1.0.1 and also tried 8.0.4 - same problem.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...