Installation

Error starting Splunk after installation: Error starting Splunkweb

deletethisaccou
Explorer

After I installed Splunk, I would start Splunk, but I get the following:
Starting splunk server daemon (splunkd)...
Timed out waiting for splunkd to start.
Starting splunkweb. Error starting splunkweb.

I use OpenSuse 11.0 x86. I followed the installationguide of splunk. The first start configuration went successfull. I don't know what I did wrong.

Thanks for help!

EDIT: I added information of the splunkd.log..

0 Karma
2 Solutions

netwrkr
Communicator

check your log files $INSTALL/var/log/splunk/splunkd.log

View solution in original post

Simeon
Splunk Employee
Splunk Employee

It looks like Splunk cannot read the splunkd.xml file to correctly which is preventing startup. I suggest you try the following:

See if /opt/splunk/etc/myinstall/splunkd.xml exists.

Verify permissions on /opt/splunk/etc/myinstall/splunkd.xml

I suspect that you may have installed over an instance in some way, where it did not create the splunkd.xml file. Reinstalling or copying over a vanilla splunkd.xml might get things working if the file is not present.

View solution in original post

poeltuyn
Engager

I had the same problem after a fresh install on linux.
I had to do the following to get things to work:

  1. [/opt/splunk/etc/myinstall] # cp splunkd.xml.cfg-default splunkd.xml
  2. [/opt/splunk/bin] # ./genRootCa.sh -d /opt/splunk/etc/auth
  3. [/opt/splunk/bin] # ./genWebCert.sh
  4. [/opt/splunk/share/splunk/search_mrsparkle] # cp -r modules.new/* modules

Now I see the splunkd and splunkweb processes starting and can I login.

Simeon
Splunk Employee
Splunk Employee

It looks like Splunk cannot read the splunkd.xml file to correctly which is preventing startup. I suggest you try the following:

See if /opt/splunk/etc/myinstall/splunkd.xml exists.

Verify permissions on /opt/splunk/etc/myinstall/splunkd.xml

I suspect that you may have installed over an instance in some way, where it did not create the splunkd.xml file. Reinstalling or copying over a vanilla splunkd.xml might get things working if the file is not present.

Pete_Bassill
Path Finder

Hi

Without wanting to sound too basic, have you checked that /opt/splunk/etc/myinstall/splunkd.xml exists? I have seen this error occur when the package did not decompress properly. You may want to check the permissions on the files too?

Pete

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I suspect you may have permissions problems if it doesn't exist, which will cause other problems even if you can get that file put in place. Did you install as a user other than the one running Splunk? You may have to change all file and directory ownerships.

0 Karma

deletethisaccou
Explorer

I think that I did not read the log carefully.. I am going to check that when I am back on the office friday...

0 Karma

deletethisaccou
Explorer

I read the following in the log-file:

04-08-2010 14:36:03.152 INFO  ulimit - Limit: virtual address space size: 4273029120 bytes [hard maximum: unlimited]
04-08-2010 14:36:03.152 INFO  ulimit - Limit: data segment size: unlimited
04-08-2010 14:36:03.152 INFO  ulimit - Limit: resident memory size: 2708336640 bytes [hard maximum: unlimited]
04-08-2010 14:36:03.152 INFO  ulimit - Limit: stack size: 8388608 bytes [hard maximum: unlimited]
04-08-2010 14:36:03.152 INFO  ulimit - Limit: core file size: 0 bytes [hard maximum: unlimited]
04-08-2010 14:36:03.152 WARN  ulimit - Core file generation disabled
04-08-2010 14:36:03.152 INFO  ulimit - Limit: data file size: unlimited
04-08-2010 14:36:03.152 INFO  ulimit - Limit: open files: 8192 files
04-08-2010 14:36:03.152 INFO  ulimit - Limit: user processes: unlimited
04-08-2010 14:36:03.153 INFO  ulimit - Limit: cpu time: unlimited
04-08-2010 14:36:03.181 INFO  loader - Splunkd starting (build 77833).
04-08-2010 14:36:03.183 INFO  loader - System info: Linux, linux-im0m, 2.6.31.5-0.1-default, #1 SMP 2009-10-26 15:49:03 +0100, i686.
04-08-2010 14:36:03.259 INFO  loader - Detected 2 (virtual) CPUs and 3038MB RAM
04-08-2010 14:36:03.261 INFO  loader - Getting configuration data from: /opt/splunk/etc/myinstall/splunkd.xml
04-08-2010 14:36:03.262 INFO  loader - Could not stat file: /opt/splunk/etc/myinstall/splunkd.xml.
04-08-2010 14:36:03.262 INFO  loader - Couldn't open file /opt/splunk/etc/myinstall/splunkd.xml
04-08-2010 14:36:03.263 ERROR loader - Error getting component configuration data from /opt/splunk/etc/myinstall/splunkd.xml
04-08-2010 14:39:51.003 INFO  ulimit - Limit: virtual address space size: 4273029120 bytes [hard maximum: unlimited]
04-08-2010 14:39:51.004 INFO  ulimit - Limit: data segment size: unlimited
04-08-2010 14:39:51.004 INFO  ulimit - Limit: resident memory size: 2708336640 bytes [hard maximum: unlimited]
04-08-2010 14:39:51.004 INFO  ulimit - Limit: stack size: 8388608 bytes [hard maximum: unlimited]
04-08-2010 14:39:51.004 INFO  ulimit - Limit: core file size: 0 bytes [hard maximum: unlimited]
0 Karma

netwrkr
Communicator

check your log files $INSTALL/var/log/splunk/splunkd.log

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...