Security

find: ‘/opt/splunkforwarder/lib/python3.7/site-packages’: No such file or directory

Gururaj1
Explorer

Getting error while downloading forwarder in  Ubuntu, 20.04 LTS, amd64 focal image built on 2025-04-08

Reinstalled, tried a bunch of commands to check for any issues, but could not find any solution. Tried different versions of the ubuntu architecture, still the same. This is stopping my instance to run splunk [ Allowed http traffic, firewall port open..etc]

cd /opt/splunkforwarder/bin/ splunk validate files

Setting up splunkforwarder (9.4.1) ...
find: ‘/opt/splunkforwarder/lib/python3.7/site-packages’: No such file or directory
find: ‘/opt/splunkforwarder/lib/python3.9/site-packages’: No such file or directory
find: ‘/opt/splunkforwarder/lib/python3.7/site-packages’: No such file or directory
find: ‘/opt/splunkforwarder/lib/python3.9/site-packages’: No such file or directory
complete

Labels (1)

KeithH
Path Finder

FYI - I got the same problem installing on a ubuntu 22.04 VM.
Splunkd is up and running though so perhaps, as suggested above, this is a red herring?

KeithH_0-1744675321230.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Gururaj1 

Splunk UF should not have a python site-packages as UF installation does not include Python. 

Please can you confirm what manifest file you have in /opt/splunkforwarder? If you are using 64-bit version it should be called splunkforwarder-9.4.1-e3bdab203ac8-linux-amd64-manifest.

This manifest file does not contain reference to the Python libraries. 

Please can you confirm the filename of the Splunk installation file you used to install the UF? 

@kiran_panchavat please can you let me know the community posts you're referring to where people with Ubuntu are having issues with UF installs so I can see if there is an underlying common issue.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Gururaj1
Explorer

@livehybrid @kiran_panchavat PFA, this is so weird, i have seen few cases like this in the community with no solution. I tried multiple OS of Linux and older versions of forwarder, but its still the same.. Please find a solution as i tried a lot of versions here...

splunkforwarder-9.4.1-e3bdab203ac8-linux-amd64-manifest

Gururaj1_0-1744620974522.png

older version 9.4.0 splunk forwarder - splunkforwarder-9.4.0-6b4ebe426ca6-linux-amd64-manifest

Gururaj1_0-1744622208231.png

 

kiran_panchavat
SplunkTrust
SplunkTrust

@Gururaj1 

The error you're encountering while trying to install or validate the Splunk Universal Forwarder (version 9.4.1) on Ubuntu 20.04 LTS (Focal Fossa, amd64) suggests issues with the installation process, specifically related to missing Python site-packages directories and possibly a corrupted or incomplete download/installation.
 
The error about missing /opt/splunkforwarder/lib/python3.7/site-packages and python3.9/site-packages suggests that Splunk’s bundled Python environment is either not installed correctly or not being detected. Splunk Universal Forwarder typically bundles its own Python environment, so this issue is likely due to a corrupted installation rather than a system Python issue.
 
 

Even if I read of many problems using Ubuntu reported by the Community members.

I don't have special reccomandations: only follow all the installation steps documented at https://docs.splunk.com/Documentation/Splunk/9.0.5/Installation/InstallonLinux  https://docs.splunk.com/Documentation/Forwarder/9.0.5/Forwarder/Installanixuniversalforwarder  but it's a very simple procedure.

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

Gururaj1
Explorer

@kiran_panchavat @livehybrid Unfortunately , there seems to be no solution for this, i tried and followed the exact steps mentioned in the given below Splunk Doc, but i encounter the same error again and again. Do u know how to mitigate this scenarios or any further suggestions on why this is happening. I tried in few of the different settings of VMs where different platforms of linux were installed along with that i increased the capacity of the OS to ensure no issues on the other side. The issue seems to residing in unbundling of the downloaded packages.

I understand installation is being corrupted but the package is being downloaded from splunk site right?

Gururaj1_0-1744628207282.png

it shows all files intact but unable to host forwarder in an instance

I am stuck here with no specific solutions...

Gururaj1_0-1744629395891.png

 

FYI -Tried different linux OS/versions, tried downgrading the SF versions as well... increased capacity of OS

livehybrid
SplunkTrust
SplunkTrust

Hi @Gururaj1 

Just to check - apart from the errors you mentioned - Does Splunk install correctly? Those errors dont necessarily mean there is an issue - its likely that part of the debian preinst script which calls a "temp_splunk-preinstall" file - this is looking for those locations to do *something* - "find" is usually used to "find" something (file/folder) and then do something to it like update permissions or something. 

If the find returns no files the script looks to continue, finally finishing with "complete" - at this point I'd expect your install to be complete - Since you splunk validate command returned a success I thing these "errors" are benign. 

The existence of them is either a mistake in that script - OR - it could be for something we arent necessarily aware of.

Either way, If the files get installed then I'm confident this isnt an issue.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Gururaj1
Explorer

Hello @livehybrid , thank you for the update, 

I would have ignored this if I was able to access the splunk UF webpage. But the issue here the webpage timeout appears and I tested the exact scenario with splunk HF and Splunk Enterprise  9.4.1 and it works perfectly fine[No errors while installation]. Am i missing something here ?

However, thank you. If you find any resolution to this, please do let me know. As the issue is unknown, not sure how to tackle..

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Gururaj1 

The UF does not have a web UI. 
Check /opt/splunkforwarder/var/log/splunk/splunkd.log to see if the server is running (it should update quite regularly)

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...