Installation

Error loading logging conf file - can't start Splunk Enterprise Server

rdjoraev_splunk
Splunk Employee
Splunk Employee

Not able to start Splunk.

When running "./splunk start" from the command line, Splunk Enterprise Server fails to start with the following error message:

Error loading logging conf file='/opt/splunk/etc/log.cfg'; runContext=splunkd

Tags (2)
1 Solution

rdjoraev_splunk
Splunk Employee
Splunk Employee

As per error message, root cause of the issue is related to log.cfg file in located the /opt/splunk/etc/ directory.

Checked in the splunkd.log file in $SPLUNK_HOME/var/log/splunk and observed the following message in it:

WARN Logger - /opt/splunk/etc/log.cfg:11: Parse error at "TailingProcessork....

It was found that the category.TailingProcessor parameter name was not spelled correctly. After updating the parameter name in the log.cfg file, user was able to start Splunk Server successfully.

View solution in original post

rdjoraev_splunk
Splunk Employee
Splunk Employee

As per error message, root cause of the issue is related to log.cfg file in located the /opt/splunk/etc/ directory.

Checked in the splunkd.log file in $SPLUNK_HOME/var/log/splunk and observed the following message in it:

WARN Logger - /opt/splunk/etc/log.cfg:11: Parse error at "TailingProcessork....

It was found that the category.TailingProcessor parameter name was not spelled correctly. After updating the parameter name in the log.cfg file, user was able to start Splunk Server successfully.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...