Installation

unable to enable boot-start in RHEL 9

Somesh
Explorer

I have downloaded splunk 9.2 rpm file and installed on rhel9.2. While i'm running splunk enable boot-start it's throwing  the error as below. 

 

[root@splunk~]# splunk enable boot-start
execve: No such file or directory
  while running command /sbin/chkconfig
[root@splunk~]#

 

 

Can someone help me on this ?

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Somesh ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

0 Karma

Somesh
Explorer

Thanks for the update @gcusello. It worked by running the command "splunk enable boot-start -systemd-managed 1". Also what is the best practice to start the splunk ? Is that needs to be started by "root" user or the "splunk" user 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Somesh ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

Somesh
Explorer

What's the best way to start the splunk ? Is it with root user or with the splunk user ? 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Somesh ,

this seems to be a different question and I hint to open a new question to be more sure to have more and probably better answers.

Anyway, Splunk best practices hint to run Splunk as not root user, for security reasons, but this gives some additional difficoultes in log reading, 

For more additional information see at https://docs.splunk.com/Documentation/Splunk/9.2.1/Installation/RunSplunkasadifferentornon-rootuser

Ciao.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...