Security

/opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory

omipenguin
New Member

I installed Splunk 8 splunk-8.0.0-1357bef0a7f6-linux-2.6-x86_64.rpm on RedHat 7.6 , it was installed under /opt later due to low space i added new disk and mount the new partition of new disk on /opt and moved all the data from original /opt to new /opt

And i tried to restart the splunk server using "systemctl restart splunk" it failed with this message

Job for splunk.service failed because the control process exited with error code. See "systemctl status splunk.service" and "journalctl -xe" for details

● splunk.service - SYSV: Splunk indexer service
   Loaded: loaded (/etc/rc.d/init.d/splunk; bad; vendor preset: disabled)
   Active: failed (Result: exit-code) since Wed 2019-11-20 10:34:15 +03; 30s ago
     Docs: man:systemd-sysv-generator(8)
  Process: 14675 ExecStop=/etc/rc.d/init.d/splunk stop (code=exited, status=0/SUCCESS)
  Process: 15594 ExecStart=/etc/rc.d/init.d/splunk start (code=exited, status=127)

Nov 20 10:34:15 logging splunk[15594]: open
Nov 20 10:34:15 logging splunk[15594]: Checking kvstore port [8191]: /opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory
Nov 20 10:34:15 logging splunk[15594]: /opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory
Nov 20 10:34:15 logging splunk[15594]: open
Nov 20 10:34:15 logging splunk[15594]: /opt/splunk/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory
Nov 20 10:34:15 logging splunk[15594]: SSL certificate generation failed.
Nov 20 10:34:15 logging systemd[1]: splunk.service: control process exited, code=exited status=127
Nov 20 10:34:15 logging systemd[1]: Failed to start SYSV: Splunk indexer service.
Nov 20 10:34:15 logging systemd[1]: Unit splunk.service entered failed state.
Nov 20 10:34:15 logging systemd[1]: splunk.service failed.

I checked the permissions for /opt/splunk are set to splunk:splunk

0 Karma

raghuramj
New Member

Try to do rsync from old directory to new directory, probably this will solves the issue.

Example command: rsync -avzh

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...