Splunk Enterprise

Cannot run splunk 9.4.3 after install on Linux

GeneralBlack
Explorer

Hello after I installed Splunk 9.4.3 on Linux (Ubuntu) I am unable to run it. When I try to start Splunk, it says the directory does not exist. When I found it in the directory, I prompted with a KVstore error message. 

Any help is greatly appreciated and needed.

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @GeneralBlack 

Please could you share the full error you are getting? 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

GeneralBlack
Explorer

"KVStore version upgrade precheck FAILED!" is the error I received

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

@GeneralBlack Please work with splunk support, may be its missing the the mongod folder and it was not created after upgrade?



If this helps, Upvote!!!!
Together we make the Splunk Community stronger 

GeneralBlack
Explorer

Hello Sainag I've tried calling Splunk customer support and keep getting thwarted in circles via the automated calling system. I've watched multiple tutorials and even some specifically given by Splunk and still no luck.

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

@GeneralBlack we might need to re-install the previous splunk version for this, best approach is to work with support.
https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.3/administer-the-app-key-valu...

Try this go to login.splunk.com > support > support portal  > Need help? > Create a Case





if this Helps, Please Upvote

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 

GeneralBlack
Explorer

Okay, I've followed the documentation for the kvstore upgrade and ensured I disabled it before as well as manually tried upgrading it still no luck. After removing mog and starting Splunk again I received the messages such a:

ERROR while running splunk-preinstall

"/opt/splunk/var/log/splunk"

 

 

 

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...