Hi ..
Splunk Forwarder is getting the following error when starting in HP UX Systems ??
this is the error in one of the log file.
splunkd started (build 149561)
/usr/lib/hpux64/dld.so: Unsatisfied code symbol '__cxa_get_exception_ptr' in load module
HP UX Vesion : HP-UX B.11.23 U ia64
Installed Forwarder Version : splunkforwarder-5.0.3-163460-HPUX-ia64.tgz
Command used to install : tar -zxvf splunkforwarder-5.0.3-163460-HPUX-ia64.tgz
I am getting the following error when i give start ...
function (from, to) {
this.splice(to, 0, this.splice(from, 1)[0]);
}
> hpux03 $ ./splunk start
>
> Splunk> Winning the War on Error
>
> Checking prerequisites...
> Checking mgmt port [8089]: open
> Checking conf files for typos... Done All preliminary
> checks passed. Starting splunk server
> daemon (splunkd)... Timed out waiting
> for splunkd to start.
hpux03 $ ./splunk status
splunkd is not running.
hpux03 $./splunk btool check
In Splunkd log file..i could see the following ..
07-15-2013 16:37:26.670 +0100 INFO LMConfig - serverName=efisapp03 guid=59BA40F8-FD5B-4C20-B07F-2A584E73DAFA
07-15-2013 16:37:26.671 +0100 INFO LMConfig - connection_timeout=30
07-15-2013 16:37:26.671 +0100 INFO LMConfig - send_timeout=30
07-15-2013 16:37:26.671 +0100 INFO LMConfig - receive_timeout=30
07-15-2013 16:37:26.671 +0100 INFO LMConfig - squash_threshold=1000
07-15-2013 16:37:26.671 +0100 INFO LicenseMgr - Initing LicenseMgr runContext_splunkd=true
07-15-2013 16:37:26.671 +0100 INFO LMStackMgr - closing stack mgr
07-15-2013 16:37:26.671 +0100 INFO LMSlaveInfo - all slaves cleared
07-16-2013 08:59:06.885 +0100 INFO LicenseMgr - Initing LicenseMgr
Tried btool check also..but its not returing any result..wat can be the issue ??
This happens if the hp-ux system has Out of date OS patches.
Thanks Antonio Bonuccelli !! I even work with laks , Seen your reply to him .. we are checking this ..will update how it goes..
i have done in the same way dart..but its not working..:(.. even i started splunk and wen i give the command list monitor splunk process is stopping..
HP UX $ ./splunk list monitor
Your session is invalid. Please login.
Splunk username: admin
Password:
Couldn't get auth token: Couldn't complete HTTP request: No error
ERROR: pid 26607 terminated with signal 9
Splunk is not running, and it must be for this operation. To start splunk, run "splunk start". (01)
One thing I'd like to double check is that the documentation says:
† You must use gnu tar to unpack the HP/UX installation archive.
You give your install command as:
tar -zxvf splunkforwarder-5.0.3-163460-HPUX-ia64.tgz
is tar
on your system gnu tar?
in splunkd_stderr.log i have following error
/usr/lib/hpux64/dld.so: Unsatisfied code symbol '__cxa_get_exception_ptr' in load module '/opt/splunkforwarder/bin/splunkd'.
hmm...i checked the splunkd.log ..but its not having any such error 😞
Hey Rakesh could you check Splunkd.log and see if the 8089 port is blocked by any chance.
Hi miteshvohra..updated my question wit the details u asked.can you help me in solving the issue please...
Can you run 'splunk btool check' and share the results? Also, if you could share the command used to install HP-UX binary for UF.
Lastly, are you using the right file for your HP-UX platform from Splunk site?
Mitesh.
hmm...yeah grijhwani..can you help me in solving this issue...i have jus installed a UF and trying to start it..but then its not starting..thought it could be the reason of not having compiler in my HP UX system..and installed it..but even then splunk fwder is not starting.. 😞
If you have to run as root that is a kludge not a proper fix. You should never have a process like Splunk as root. It is far too open to abuse. The correct response is what the user is trying to do - find the real fault and fix it.
The mentioned error i dont think is the cause. Please give the splunkforwarder folder full access. Run the forwarder under root. use splunk btool to check whether all the settings are correct or not. The receving port needs to be configured on indexers
how do i check tat pls ? i have installed a UF in HP UX system..and when starting the splunk ..its throwing this error ?? can you pls help here..
is the receiving port configured?