Deployment Architecture

Why does AIX Splunk universal forwarder installation hang after input username?

noobsplunker_
Loves-to-Learn Lots

Hi guys,

This is the first time I'm trying to install splunk universal forwarder (8.2.2.1) on an AIX (7.1) machine.  I have no previous experience with AIX, but have installed many on Linux/Unix machines. The issue I seem to get is when I'm done installing, and splunk prompts for a user/password, the entire process hangs after I've input the username. The only way out is to kill the PID or exit the machine.

Steps taken: 

I have downloaded the tgz file, expanded the tar with: gunzip -c "filename.tar.gz" | tar -xvf, to the /opt folder

Changed ownership with : chown -R splunk:splunk /splunk/splunkforwarder

Switched to splunk user to install : su - splunk

Run on $/SPLUNK_HOME/bin:  ./splunk start --accept license

Select Y

Enter username, and this is where is  stops

 

Any suggestions would be kindly appreciated 

 

0 Karma

gcusello
Legend
0 Karma

noobsplunker_
Loves-to-Learn Lots

Hi @gcusello ,

Thanks for your reply. 

I have followed the AIX installation guide as recommended and deleted off all old splunkforwarder files, starting with a fresh installation . 

After unzipping the file to opt/splunk/$SPLUNK_HOME, 

changing ownership: chown -R splunk:splunk

su - splunk

The process still hangs after running  $SPLUNK_HOME/bin/./splunk enable boot-start, right at the beginning when prompting for the splunk administrator username.

splunk aix.PNG

It did not even get to the prompt below :
This command invokes the following system commands to register the forwarder in the System Resource Controller (SRC):

mkssys -G splunk -s splunkd -p <path to splunkd> -u <splunk user> -a _internal_exec_splunkd -S -n 2 -f 9


Is there any way for me to check logs for any errors or dump files? I am not able to create a diag file via ./splunk diag as splunk is not yet installed

I tried running netstat to look for any splunkd processes or common ports such as 8000, 8080, 8089, or 9997 to no avail

This AIX machine has the same resources as all other machines so there shouldn't be a resource bottleneck.


splunk universal forwarder (8.2.2.1) on an AIX (7.1) machine, 


Thanks!



0 Karma

gcusello
Legend

Hi @noobsplunker_,

see in $SPLUNK_HOME/var/log/splunk if there's an installation log.

Anyway, open a case to Splunk Support: I had many problems on AIX, especially in restarting.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...