Splunk SOAR

Alma Linux 9.6 soar-prepare-system FAILED

Michal_Slezak
Engager

Dear community,

I would like to ask for help
Currently we are trying to run SOAR instance in LAB env , we are using Alma Linux

etc/os-release

NAME="AlmaLinux"
VERSION="9.6 (Sage Margay)"
ID="almalinux"
ID_LIKE="rhel centos fedora"
VERSION_ID="9.6"
PLATFORM_ID="platform:el9"

when I run /opt/phantom/splunk-soar/soar-prepare-system

Detailed logs will be located at /opt/phantom/var/log/phantom/phantom_install_log
Preparing system for installation of Splunk SOAR 6.4.1.361
local variable 'platform' referenced before assignment
Pre-install failed.

Any ideas? I already read supported OS versions but Alma Linux 9.x should be fine since RHEL 9 is supported.

Thank you for any inputs

Labels (2)
0 Karma

kokyi
New Member

I use rocky linux 8. I need to modify /etc/os-release file to be the same as the one for Redhat. Then, I am able to install the splunk soar on it. But I am not sure it will work properly since I didn't tested it.

0 Karma

Michal_Slezak
Engager

Thank you guys for valuable inputs, I installed it on Oracle Linux 9 without any problem.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Alma is not officially supported. It is "relatively close" to RHEL (although not fully 100% bug-for-bug compatible). It can be installed but it requires some tweaking of the install script (as far as I remember, it checks for supported distros so it will refuse to install unless you force it to). Still - it might be a way to run the community version in lab environment but it will not be supported so I wouldn't go prod with it.

livehybrid
SplunkTrust
SplunkTrust

Its also worth noting that, as you have highlighted, Alma Linux is not supported. Despite it being based on RHEL it *isnt* RHEL and therefore certain commands/libraries may be different or unavailable.

I have seen this error previously on Rocky Linux which I believe is also RHEL based but ultimately did not work for SOAR.

If possible please try the installation using RHEL9 and see if the issue goes away. You will be limited in terms of support from Splunk if not using a supported OS and any "fixes" to make the installation work may not persist and may cause other issues down the line.

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

livehybrid
SplunkTrust
SplunkTrust

Hi @Michal_Slezak 

Were there any more detailed log in /opt/phantom/var/log/phantom/phantom_install_log which might give us more information about the platform variable referenced which it seems to be failing on?

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...