![]() ![]() Process: 3141480 ExecStartPost=/bin/bash -c chown -R splunk:splunk /sys/fs/cgroup/memory/system.slice/rvice (code=exited, status=0/SUCCES> Loaded: loaded (/etc/systemd/system/rvice enabled vendor preset: disabled)Īctive: failed (Result: exit-code) since Tue 12:58:55 UTC 27s ago rvice - Systemd service file for Splunk, generated by 'splunk enable boot-start'.See "systemctl status rvice" and "journalctl -xe" for details. Job for rvice failed because the control process exited with error code. Systemd unit file installed by user at /etc/systemd/system/rvice. # /opt/splunkforwarder/bin/splunk enable boot-start -user splunk Please wait, as this may take a few minutes. # sudo -H -u splunk /opt/splunkforwarder/bin/splunk stop Splunk helpers are running (PIDs: 3132354). Sudo -H -u splunk /opt/splunkforwarder/bin/splunk status Please create it manually by 'sudo splunk enable boot-start' later.įailed to create the unit file. You will have to set up an admin username/passwordĬurrent splunk is running as non root, which cannot operate systemd unit files. IMPORTANT: Because an admin password was not provided, the admin user This appears to be your first time running this version of Splunk. # sudo -H -u splunk /opt/splunkforwarder/bin/splunk start -accept-license -answer-yes -no-prompt Warning: Attempting to revert the SPLUNK_HOME ownershipĬhown -R splunk:splunk /opt/splunkforwarder Runuser -l splunk -c "/opt/splunkforwarder/bin/splunk status" Runuser -l splunk -c "/opt/splunkforwarder/bin/splunk start -accept-license -answer-yes -no-prompt" Tar -xzvf /tmp/splunkforwarder-9.0.0-6818ac46f2ec-Linux-x86_64.tgz -C /optĬhown -R splunk:splunk /opt/splunkforwarder/ Runuser -l splunk -c "/opt/splunkforwarder/bin/splunk stop" A key error I am seeing is "Failed to create the unit file" when running the install. I am also finding that "./splunk disable boot-start" does not correctly remove the /etc/init.d/splunk script and, contrary to documentation, splunk UF 9.0.0 uses systemd as default.Īlso systemd scripts seem to fail getting the permissions needed even when trying to enable-boot as root. Warning: Executing "chown -R splunk /opt/splunkforwarder" So either, the hashing needs to stop or needs to work.Is anyone else running into boot-start/permissions issues with the 9.0.0 UF running on Linux using init.d scripts for bootstart? Warning: Attempting to revert the SPLUNK_HOME ownership Openssl rsa -in /logs/splunk_forwarder/etc/auth/server.pem -textĮnter pass phrase for /logs/splunk_forwarder/etc/auth/server.pem: When I check the password of the server.pem file using openssl: I don't have an issue with the hashing, but I feel that it has to do with the SSL error I am getting: But it is hashed when I used any of the locations above, where I consider paths 2 and 3 to be an app path. The note claims that the password will not be hashed if located in an app. The sslPassword has been hashed, just as it mentions here - in the note for #2. bin/splunk cmd btool outputs list -debug bin/splunk restart splunkdĤ) Use btool to check outputs again and note the sslPassword again. System = falseįorwarder įorwarder sslCertPath = $SPLUNK_HOME/etc/auth/server.pemįorwarder sslRootCAPath = $SPLUNK_HOME/etc/auth/cacert.pemģ) Restart splunkd. System forwardedindex.2.whitelist = _audit ![]() No matter which of these paths I choose, I continue to run into this pattern:ġ) Update nf to have a sslPassword of "password"Ģ) Use btool to check outputs and note the sslPassword. I've changed the location of my nf quite a few times, trying these paths:Ģ). I am using the default certs and the default password "password". To reiterate the issue - I am trying to enable SSL in my nf for one of my forwarders. Along the lines of this question -, but I've tried a few additional things I'd like to note. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |