Installation

Why am I getting an error installing Splunk on Mac OS High Sierra 10.13, even after adding OPTIMISTIC?

ZeinaIbrahim7
Engager

Can someone please help me fix this issue. I am trying to install Splunk on my Mac OS High Sierra 10.13 but have been getting this:

homePath='/Applications/Splunk/var/lib/splunk/audit/db' of index=_audit on unusable filesystem.

Validating databases (splunkd validatedb) failed with code '1'. If you cannot resolve the issue(s) above after consulting documentation, please file a case online at http://www.splunk.com/page/submit_issue

I have tried to append OPTIMISTIC_ABOUT_FILE_LOCKING = 1to the splunk-launch.conf but it doesn't seem to make a difference.

Can someone please help?

Any help would be greatly appreciated.

Thanks

Labels (1)

skoelpin
SplunkTrust
SplunkTrust

I've been running Splunk on Mac for years with no issues.

This may help.. I would run it in a test environment first before applying in production

https://answers.splunk.com/answers/585512/importerror-symbol-not-found-inflatevalidate-when.html

0 Karma

ZeinaIbrahim7
Engager

Hi,
Thanks for your answer. I tried running the sudo commands as suggested in your link and I get this message:
rm: /opt/splunk/lib/libz.1.dylib: No such file or directory

This is strange because I can see the file libs.1.dylib but it still says that it doesn't exist.
Running out of ideas about how to fix this and start using Splunk...

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Your Splunk home path is under /Applications/Splunk/ and you are trying under /opt/splunk. Change your directory to hit your home path

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Did this work for you? @ZeinaIbrahim7

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...