Splunk Enterprise

Installing Splunk 8.1.0 - Ubuntu 20.4 warning message

duncandka
Engager

Hi,

Installing Enterprise 8.1.0 on Ubuntu 20.4 when unpacking get the following message.
cp: cannot stat '/opt/splunk/etc/regid.2001-12.com.splunk-Splunk-Enterprise.swidtag': No such file or directory
Where as, it is directly under /opt/splunk

Duncan

 

 

Labels (1)

jeffh-cf
Engager

I just tried upgrading from Spunk Enterprise 8.1.3 to 8.2.0 on Ubuntu 20.04 and ran into the same issue but it doesn't look like the upgrade failed.

sudo dpkg -i splunk-8.2.0-e053ef3c985f-linux-2.6-amd64.deb
(Reading database ... 176294 files and directories currently installed.)
Preparing to unpack splunk-8.2.0-e053ef3c985f-linux-2.6-amd64.deb ...
This looks like an upgrade of an existing Splunk Server. Attempting to stop the installed Splunk Server...
Stopping splunkd...
Shutting down. Please wait, as this may take a few minutes.

Stopping splunk helpers...

Done.
Unpacking splunk (8.2.0) over (8.1.3) ...
Setting up splunk (8.2.0) ...
cp: cannot stat '/opt/splunk/etc/regid.2001-12.com.splunk-Splunk-Enterprise.swidtag': No such file or directory
complete

Even though the upgrade didn't appear to fail, I followed the same advice:

cp splunk-Splunk-Enterprise-primary.swidtag /opt/splunk/etc/regid.2001-12.com.splunk-Splunk-Enterprise.swidtag

I ran the installation again, and it completed successfully:

sudo dpkg -i splunk-8.2.0-e053ef3c985f-linux-2.6-amd64.deb
(Reading database ... 180376 files and directories currently installed.)
Preparing to unpack splunk-8.2.0-e053ef3c985f-linux-2.6-amd64.deb ...
This looks like an upgrade of an existing Splunk Server. Attempting to stop the installed Splunk Server...
splunkd is not running.
Unpacking splunk (8.2.0) over (8.2.0) ...
Setting up splunk (8.2.0) ...
complete

0 Karma

vishaltv
Path Finder

++ Apologies, I missed to add a step ; reposting the same 
===========================================


I faced same issue while installing 8.1.1 in ubuntu. 

Setting up splunk (8.1.1) ...
cp: cannot stat '/opt/splunk/etc/regid.2001-12.com.splunk-Splunk-Enterprise.swidtag': No such file or directory
complete

And when I checked, I could see a folder /opt/splunk/swidtag/  and a file "splunk-Splunk-Enterprise-primary.swidtag"

I copied it to "/opt/splunk/etc/"  and  renamed it to "regid.2001-12.com.splunk-Splunk-Enterprise.swidtag'" 

Change Owner of the file :

 /opt/splunk/etc# chown splunk:splunk regid.2001-12.com.splunk-Splunk-Enterprise.swidtag

Install again and it Worked!!

sudo dpkg -i splunk-8.1.1-08187535c166-linux-2.6-amd64.deb
(Reading database ... 265846 files and directories currently installed.)
Preparing to unpack splunk-8.1.1-08187535c166-linux-2.6-amd64.deb ...
This looks like an upgrade of an existing Splunk Server. Attempting to stop the installed Splunk Server...
splunkd is not running.
Unpacking splunk (8.1.1) over (8.1.1) ...
Setting up splunk (8.1.1) ...
complete

vishaltv
Path Finder

I faced same issue while installing 8.1.1 in ubuntu. 

Setting up splunk (8.1.1) ...
cp: cannot stat '/opt/splunk/etc/regid.2001-12.com.splunk-Splunk-Enterprise.swidtag': No such file or directory
complete

And we I checked, I could see a folder /opt/splunk/swidtag/  and a file "splunk-Splunk-Enterprise-primary.swidtag"

I copied it to "/opt/splunk/etc/"  and  renamed it to "regid.2001-12.com.splunk-Splunk-Enterprise.swidtag'" 

 

Install again and it Worked!!

sudo dpkg -i splunk-8.1.1-08187535c166-linux-2.6-amd64.deb
(Reading database ... 265846 files and directories currently installed.)
Preparing to unpack splunk-8.1.1-08187535c166-linux-2.6-amd64.deb ...
This looks like an upgrade of an existing Splunk Server. Attempting to stop the installed Splunk Server...
splunkd is not running.
Unpacking splunk (8.1.1) over (8.1.1) ...
Setting up splunk (8.1.1) ...
complete

bilalbox
Engager

Thanks! This also worked for install Splunk version 8.1.3 on Ubuntu 18.04 running in Azure.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Check file ownership (root or splunk). Check the user splunk is executing as. Also, check whether file locking is supported by the OS.

0 Karma

mannyzepeda
Explorer

Had the same issue -- fit appears to be an issue with the debian package. I installed the older version 8.07 over the "newer" version and the issue is fixed

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...