Installation

Solaris 11 express - start Splunk as user splunk

kronos121
Explorer

Hello all,

I have problem with starting Splunk 4.2 as user "splunk" on Solaris 11 express. Starting Splunk with root permissions is working OK.

When running Splunk with splunk user I get following error:

ld.so.1: splunkd: fatal: libpcre.so.0: open failed: No such file or directory

Splunk> See your world. Maybe wish you hadn't.

Checking prerequisites... Checking mgmt port [8089]: open Checking configuration... Done. Checking index directory... ld.so.1: splunkd: fatal: libpcre.so.0: open failed: No such file or directory ERROR: pid 7945 terminated with signal 9


Do you know how to fix this error? Thank you in advance and kind regards, Marko:)

Some additional info: Follwoing command were issued:

rolemod -K defaultpriv=basic,net_privaddr,proc_exec,proc_fork splunk

chown -R splunk:splunk /opt/splunk

ls -ls /opt/splunk/lib

....

1 lrwxrwxrwx 1 root root 16 Mar 21 20:24 libpcre.so -> libpcre.so.0.0.1

1 lrwxrwxrwx 1 root root 16 Mar 21 20:24 libpcre.so.0 -> libpcre.so.0.0.1

204 -r-xr-xr-x 1 splunk splunk 189036 Mar 11 12:38 libpcre.so.0.0.1

1 lrwxrwxrwx 1 root root 19 Mar 21 20:24 libsqlite3.so -> libsqlite3.so.0.8.6

....

Tags (1)
0 Karma
1 Solution

kronos121
Explorer

Found the problem. I have made a mistake in exec_attr.

View solution in original post

0 Karma

kronos121
Explorer

Found the problem. I have made a mistake in exec_attr.

0 Karma

MuS
SplunkTrust
SplunkTrust

hi kronos

what's the result of this command as user splunk?

ldd /opt/splunk/bin/splunkd | grep not

maybe you got some env mismatch?

kronos121
Explorer

Hi Mus,

ldd /opt/splunk/bin/splunkd | grep not
ld.so.1: splunkd: fatal: libpcre.so.0: open failed: No such file or directory
ldd: /opt/splunk/bin/splunkd: execution failed due to signal 9

If I run as root

find / -name "libpcre.so.0"

/opt/splunk/lib/libpcre.so.0

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...