Splunk on Ubuntu 16.04ios
grub-mkconfig -o /boot/grub/grub.cfgide
rebootspa
if using ntp, then stop and remove it
systemctl stop ntp
update-rc.d ntp disable
sysv-rc-conf to confirm
apt-get -y remove ntporm
using timesyncd service
vi /etc/systemd/timesyncd.conf
NTP=0.cn.pool.ntp.org 1.cn.pool.ntp.orgserver
systemctl start systemd-timesyncd
systemctl status systemd-timesyncdip
Disable Transparent Huge Page
vi /etc/systemd/system/disable-thp.service
[Unit]
Description=Disable Transparent Huge Pages (THP)rem
[Service]
Type=simple
ExecStart=/bin/sh -c "echo 'never' > /sys/kernel/mm/transparent_hugepage/enabled && echo 'never' > /sys/kernel/mm/transparent_hugepage/defrag && echo '0' > /sys/kernel/mm/transparent_hugepage/khugepaged/defrag"get
[Install]
WantedBy=multi-user.targetit
systemctl daemon-reload
systemctl start disable-thp
systemctl enable disable-thpio
reboot to take effect, ulimit -a to check
install splunk enterprise
under root privilege:
useradd -m splunk
tar zxf splunk.xxx.xxx.gz -C /opt
chown -R splunk:splunk /opt/splunk
su - splunk
/opt/splunk/bin/splunk start --accept-license
/opt/splunk/bin/splunk enable boot-start -user splunk ( should use root permission to run )