Installation

Solaris 11 express - start Splunk as user splunk

kronos121
Explorer

Hello all,

I have problem with starting Splunk 4.2 as user "splunk" on Solaris 11 express. Starting Splunk with root permissions is working OK.

When running Splunk with splunk user I get following error:

ld.so.1: splunkd: fatal: libpcre.so.0: open failed: No such file or directory

Splunk> See your world. Maybe wish you hadn't.

Checking prerequisites... Checking mgmt port [8089]: open Checking configuration... Done. Checking index directory... ld.so.1: splunkd: fatal: libpcre.so.0: open failed: No such file or directory ERROR: pid 7945 terminated with signal 9


Do you know how to fix this error? Thank you in advance and kind regards, Marko:)

Some additional info: Follwoing command were issued:

rolemod -K defaultpriv=basic,net_privaddr,proc_exec,proc_fork splunk

chown -R splunk:splunk /opt/splunk

ls -ls /opt/splunk/lib

....

1 lrwxrwxrwx 1 root root 16 Mar 21 20:24 libpcre.so -> libpcre.so.0.0.1

1 lrwxrwxrwx 1 root root 16 Mar 21 20:24 libpcre.so.0 -> libpcre.so.0.0.1

204 -r-xr-xr-x 1 splunk splunk 189036 Mar 11 12:38 libpcre.so.0.0.1

1 lrwxrwxrwx 1 root root 19 Mar 21 20:24 libsqlite3.so -> libsqlite3.so.0.8.6

....

Tags (1)
0 Karma
1 Solution

kronos121
Explorer

Found the problem. I have made a mistake in exec_attr.

View solution in original post

0 Karma

kronos121
Explorer

Found the problem. I have made a mistake in exec_attr.

0 Karma

MuS
Legend

hi kronos

what's the result of this command as user splunk?

ldd /opt/splunk/bin/splunkd | grep not

maybe you got some env mismatch?

kronos121
Explorer

Hi Mus,

ldd /opt/splunk/bin/splunkd | grep not
ld.so.1: splunkd: fatal: libpcre.so.0: open failed: No such file or directory
ldd: /opt/splunk/bin/splunkd: execution failed due to signal 9

If I run as root

find / -name "libpcre.so.0"

/opt/splunk/lib/libpcre.so.0

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...