Security

/opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory

omipenguin
New Member

I installed Splunk 8 splunk-8.0.0-1357bef0a7f6-linux-2.6-x86_64.rpm on RedHat 7.6 , it was installed under /opt later due to low space i added new disk and mount the new partition of new disk on /opt and moved all the data from original /opt to new /opt

And i tried to restart the splunk server using "systemctl restart splunk" it failed with this message

Job for splunk.service failed because the control process exited with error code. See "systemctl status splunk.service" and "journalctl -xe" for details

● splunk.service - SYSV: Splunk indexer service
   Loaded: loaded (/etc/rc.d/init.d/splunk; bad; vendor preset: disabled)
   Active: failed (Result: exit-code) since Wed 2019-11-20 10:34:15 +03; 30s ago
     Docs: man:systemd-sysv-generator(8)
  Process: 14675 ExecStop=/etc/rc.d/init.d/splunk stop (code=exited, status=0/SUCCESS)
  Process: 15594 ExecStart=/etc/rc.d/init.d/splunk start (code=exited, status=127)

Nov 20 10:34:15 logging splunk[15594]: open
Nov 20 10:34:15 logging splunk[15594]: Checking kvstore port [8191]: /opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory
Nov 20 10:34:15 logging splunk[15594]: /opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory
Nov 20 10:34:15 logging splunk[15594]: open
Nov 20 10:34:15 logging splunk[15594]: /opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory
Nov 20 10:34:15 logging splunk[15594]: SSL certificate generation failed.
Nov 20 10:34:15 logging systemd[1]: splunk.service: control process exited, code=exited status=127
Nov 20 10:34:15 logging systemd[1]: Failed to start SYSV: Splunk indexer service.
Nov 20 10:34:15 logging systemd[1]: Unit splunk.service entered failed state.
Nov 20 10:34:15 logging systemd[1]: splunk.service failed.

I checked the permissions for /opt/splunk are set to splunk:splunk

0 Karma

raghuramj
New Member

Try to do rsync from old directory to new directory, probably this will solves the issue.

Example command: rsync -avzh

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...