Security

/opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory

omipenguin
New Member

I installed Splunk 8 splunk-8.0.0-1357bef0a7f6-linux-2.6-x86_64.rpm on RedHat 7.6 , it was installed under /opt later due to low space i added new disk and mount the new partition of new disk on /opt and moved all the data from original /opt to new /opt

And i tried to restart the splunk server using "systemctl restart splunk" it failed with this message

Job for splunk.service failed because the control process exited with error code. See "systemctl status splunk.service" and "journalctl -xe" for details

● splunk.service - SYSV: Splunk indexer service
   Loaded: loaded (/etc/rc.d/init.d/splunk; bad; vendor preset: disabled)
   Active: failed (Result: exit-code) since Wed 2019-11-20 10:34:15 +03; 30s ago
     Docs: man:systemd-sysv-generator(8)
  Process: 14675 ExecStop=/etc/rc.d/init.d/splunk stop (code=exited, status=0/SUCCESS)
  Process: 15594 ExecStart=/etc/rc.d/init.d/splunk start (code=exited, status=127)

Nov 20 10:34:15 logging splunk[15594]: open
Nov 20 10:34:15 logging splunk[15594]: Checking kvstore port [8191]: /opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory
Nov 20 10:34:15 logging splunk[15594]: /opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory
Nov 20 10:34:15 logging splunk[15594]: open
Nov 20 10:34:15 logging splunk[15594]: /opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory
Nov 20 10:34:15 logging splunk[15594]: SSL certificate generation failed.
Nov 20 10:34:15 logging systemd[1]: splunk.service: control process exited, code=exited status=127
Nov 20 10:34:15 logging systemd[1]: Failed to start SYSV: Splunk indexer service.
Nov 20 10:34:15 logging systemd[1]: Unit splunk.service entered failed state.
Nov 20 10:34:15 logging systemd[1]: splunk.service failed.

I checked the permissions for /opt/splunk are set to splunk:splunk

0 Karma

raghuramj
New Member

Try to do rsync from old directory to new directory, probably this will solves the issue.

Example command: rsync -avzh

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...