Reporting

Splunk reports first-time run failed!

aagashe
Engager

Hi Guys,

I tried to run Splunk but it gives errors as below:

[splunk@ip-172-31-10-67 bin]$ sudo ./splunk enable boot-start -user splunk --accept-license

Warning: cannot create "/opt/splunk/var/log/splunk"

Warning: cannot create "/opt/splunk/var/log/introspection"

Warning: cannot create "/opt/splunk/var/log/watchdog"
Warning: cannot create "/opt/splunk/etc/licenses/download-trial"
First-time run failed!

[splunk@ip-172-31-10-67 bin]$ sudo ./splunk start --accept-license

Warning: cannot create "/opt/splunk/var/log/splunk"

Warning: cannot create "/opt/splunk/var/log/introspection"

Warning: cannot create "/opt/splunk/var/log/watchdog"
Warning: cannot create "/opt/splunk/etc/licenses/download-trial"

How to resolve these warnings? Also is it possible to provide a response file when we run the Splunk for the first time so I do not have to type the responses thereby we can automate without manual intervention?

Please assist.

Tags (1)
0 Karma

PavelP
Motivator

Hello @aagashe,

it looks like a permission issue, the splunk folders and files belong to other user (or root?) or splunk is already running. It happens often if splunk installed from tgz.

Run with root privileges (change the $SPLUNK_HOME as appropriate):

sudo pkill -f splunk
sudo chown -R splunk:splunk /opt/splunk
sudo /opt/splunk/bin/splunk enable boot-start -user splunk --accept-license
sudo systemctl start splunk

The modern way to run Splunk is using systemd, so you can change it to:

    sudo pkill -f splunk
    sudo chown -R splunk:splunk /opt/splunk
    sudo ./splunk enable boot-start -user splunk -systemd-managed 1 --accept-license
    sudo systemctl start Splunkd

if you choose the last method, stick to it and start/stop splunk using "sudo systemctl" only.

aagashe
Engager

Ok, how to provide username and password? When I run for the first time I have to provide username and password, I was thinking if there is a response file so that part can be automated as well.

Please guide.

Thank you.

0 Karma

PavelP
Motivator
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...