Splunk ITSI

"Unable to retrieve Java version on this machine, make sure Java is properly installed"

Jarohnimo
Builder

Java JDK 8 installed on the machine (Windows Server 2012 R2) yet i get this message.

I'm running ITSI ontop of the latest version of Splunk
he functionality that requires ITSI is anomaly detection but isn't working for whatever reason and I get this message.

0 Karma

michael_mcgrail
Engager

I know this question is fairly old, but in case anyone else comes across this:
We had this same issue with ITSI on RedHat. Even with JRE installed and working, we found to issues:
1. Splunk /etc/splunk-launch.conf was owned by root for some reason so we chown splunk:splunk the entire directory again
2. We still had to update /etc/splunk-launch.conf to include JAVA_HOME=/usr/java/jre1.8.0_211/ The documentation says this is not required if PATH or JAVA_HOME are set, but we found we had to set all 3 (JAVA_HOME, PATH and also specify in splunk-launch.conf).

0 Karma

mwdbhyat
Builder

Does the user have permission to run/access this? Has the Java service started correctly?

0 Karma

sylbaea
Communicator

@mwdbhyat I have same problem... In my case, no permission issue but what do you mean by "Java service started"

0 Karma

493669
Super Champion

@Jarohnimo , are you able to resolve your issue?

0 Karma

Jarohnimo
Builder

No, I just gave up on that functionality. I consider it a bug as from all my searches there's no clear answer

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...