Splunk Enterprise

Cannot run splunk 9.4.3 after install on Linux

GeneralBlack
Explorer

Hello after I installed Splunk 9.4.3 on Linux (Ubuntu) I am unable to run it. When I try to start Splunk, it says the directory does not exist. When I found it in the directory, I prompted with a KVstore error message. 

Any help is greatly appreciated and needed.

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @GeneralBlack 

Please could you share the full error you are getting? 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

GeneralBlack
Explorer

"KVStore version upgrade precheck FAILED!" is the error I received

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

@GeneralBlack Please work with splunk support, may be its missing the the mongod folder and it was not created after upgrade?



If this helps, Upvote!!!!
Together we make the Splunk Community stronger 

GeneralBlack
Explorer

Hello Sainag I've tried calling Splunk customer support and keep getting thwarted in circles via the automated calling system. I've watched multiple tutorials and even some specifically given by Splunk and still no luck.

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

@GeneralBlack we might need to re-install the previous splunk version for this, best approach is to work with support.
https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.3/administer-the-app-key-valu...

Try this go to login.splunk.com > support > support portal  > Need help? > Create a Case





if this Helps, Please Upvote

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 

GeneralBlack
Explorer

Okay, I've followed the documentation for the kvstore upgrade and ensured I disabled it before as well as manually tried upgrading it still no luck. After removing mog and starting Splunk again I received the messages such a:

ERROR while running splunk-preinstall

"/opt/splunk/var/log/splunk"

 

 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...