Installation

UF 32 bit vs 64 bit

ameet
Explorer

Hi!!
I'm very new to Splunk and just want some advise.  I accidentally installed a 32 bit version of the universal forwarder on my test linux machine.  is it fine to install the 64 bit version on top without removing the 32bit version and will this cause issues later?  i'm also running splunk web on the same linux machine too. 

any advise or suggestion please. 

Amit 

Labels (1)
0 Karma

ameet
Explorer

Thank you @gcusello and @isoutamo for your suggestions. And yes i agree should have checked and plan better. Yes it is the Splunk Enterprise single instance installation. 
Just to ellaborate a little bit more - i untar the UF installtion file and then tried starting the UFs from the bin folder using sudo ./splunk start command but i ended up getting the error message below 

ameet_0-1734434822638.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
As this is your clean new installation on your test machine, I propose that you remove whole UF installation (probably in /opt/splunkforwarder or something similar). Then if you really want to install also UF on the same machine install it with your package manager from rpm or dpg file. Then just try to start it again. Just follow UF’s installation instructions from docs.splunk.com.

ameet
Explorer

Yes thats what i did and its working now - thanks for your advises. 

Cheers 

gcusello
SplunkTrust
SplunkTrust

Hi @ameet ,

let us know if we can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

gcusello
SplunkTrust
SplunkTrust

Hi @ameet ,

the 32 bit UF should run on a 64 bit OS, but it's always better to have the correct version!

You can override installation, even if it's better to remove the old installation.

To avoid this kind of issues, It's always better to plan the installation, creating (e.g. on Excel) a list of destination systems with the OS and architecture of each one, to avoid to install the wrong version.

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust
You said, that you are running Splunk Web also in this machine. Do you mean Splunk Enterprise in single instance installation? If so then you don’t need / should run separate UF on same box. You can collect everything with it as with UF and actual much more if needed.
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...