Installation

Receiving the following error: "failed to start splunk.service: unit splunk.service not found"/ SplunkForwarder.service

Qyusuff
New Member

Been receiving this error from my UF. extremely frustrating since splunk doesn't offer any support unless your paying them.

-did then system daemon reload 

- enable/disable boot-start

- reviewed splunkd.log

-Somtimes it would say splunk.pid doesnt exist.

-What the hell is going on here, failures for both  Ubuntu and AWS

Splunk FW: Receiving the following error: "failed to start splunk.service: unit splunk.service not found"

SplunkForwarder.service - Systemd service file for Splunk, generated by 'splunk enable boot-start'
Loaded: error (Reason: Unit SplunkForwarder.service failed to load properly, please adjust/correct and reload service manager: Device or resource busy)
Active: failed (Result: signal) since Wed 2024-01-17 20:04:18 UTC; 13s ago
Duration: 1min 48.199s
Main PID: 14888 (code=killed, signal=KILL)
CPU: 2.337s

 

Labels (1)
0 Karma

kairobin
Path Finder

Hello
We also got this issue.
Did you find any answer or solution?

When installing SplunkForwarder.service have enabled boot start
But after at reboot it is changed to disabled boot start. 

We clearly can not be the only ones experienced this. 

This is running on a Red Hat Plow
and running UF version 9

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Qyusuff 

The UF version details  and ubuntu version please

was it working previously and recently you receive this error?  any recent changes, upgrades, etc?

the UF was installed manually or thru tools like chef/puppet/salt?

may i know if you had a look at the splunk log files at that UF.. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...