Monitoring Splunk

My splunk instance no longer starts: 'The value of env var SPLUNK_OS_USER, "splunker", does not match any user on this system; exiting. Success

bcapuyan
New Member

Hi Everyone,

I can no longer start my splunk instance with the command #sudo ./splunk start. I get the following error.

The value of env var SPLUNK_OS_USER, "splunker", does not match any user on this system; exiting.: Success

I was prompted to restart my splunk service after I removed/ disabled receiving from another Splunk Forwarder. I also tried to upgrade from 6.1 to 6.2 and still get the same error.

Any help?

Thank you
-Bon

Tags (1)
0 Karma
1 Solution

MuS
Legend

Hi bcapuyan,

Check the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/Admin/Splunk-launchconf and then your splunk-launch.conf

Cheers, MuS

View solution in original post

MuS
Legend

Hi bcapuyan,

Check the docs http://docs.splunk.com/Documentation/Splunk/6.2.0/Admin/Splunk-launchconf and then your splunk-launch.conf

Cheers, MuS

bcapuyan
New Member

Thanks I just commented out the SPLUNK_OS_USER=splunker line and it started like a charm

SPLUNK_OS_User=splunker

0 Karma

MuS
Legend
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...