Splunk Enterprise

Cannot run splunk 9.4.3 after install on Linux

GeneralBlack
Explorer

Hello after I installed Splunk 9.4.3 on Linux (Ubuntu) I am unable to run it. When I try to start Splunk, it says the directory does not exist. When I found it in the directory, I prompted with a KVstore error message. 

Any help is greatly appreciated and needed.

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @GeneralBlack 

Please could you share the full error you are getting? 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

GeneralBlack
Explorer

"KVStore version upgrade precheck FAILED!" is the error I received

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

@GeneralBlack Please work with splunk support, may be its missing the the mongod folder and it was not created after upgrade?



If this helps, Upvote!!!!
Together we make the Splunk Community stronger 

GeneralBlack
Explorer

Hello Sainag I've tried calling Splunk customer support and keep getting thwarted in circles via the automated calling system. I've watched multiple tutorials and even some specifically given by Splunk and still no luck.

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

@GeneralBlack we might need to re-install the previous splunk version for this, best approach is to work with support.
https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.3/administer-the-app-key-valu...

Try this go to login.splunk.com > support > support portal  > Need help? > Create a Case





if this Helps, Please Upvote

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 

GeneralBlack
Explorer

Okay, I've followed the documentation for the kvstore upgrade and ensured I disabled it before as well as manually tried upgrading it still no luck. After removing mog and starting Splunk again I received the messages such a:

ERROR while running splunk-preinstall

"/opt/splunk/var/log/splunk"

 

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...