Splunk Enterprise

Upgrade Splunk Ent. 9.2.4 to 9.3.0 - error: not found SSLEAY32.dll (and libeay32.dll)

apietersen
Contributor

During upgrade of our Splunk Ent. (production) 9.2.4 to 9.30 - throws an error: not found SSLEAY32.dll (+libeay32.dll) Nb. Splunk is installed on drive "d:\program files\Splunk

apietersen_0-1733569686665.png

 

Rebooted our Windows 2019 server and tried again, but with the same result.

Yes, I found a SSLEAY32 and LIB32 file in the folder "D:\Program Files\splunk\bin"!?

I have no idea what to do now and I am very reluctant to experiment further - although I have found similar problems on the internet, not specific related to Splunk. Does anyone have a tip or a suggestion for me waht to do next?

For example: Can I skip 9.3.0 and continue with 9.3.1 or 9.3.2?

Thanks for all the responses

AshleyP

Labels (1)
0 Karma

apietersen
Contributor

Summarize and finishing this post:

After installing Splunk Ent v9.3.2 the initial problems were solved.

  • After that it appears that Splunk Secure Gateways did not connect anymore (Splunk Mobile)
  • Had contact with Splunk about this.
  • After some back and forth copying of backup directories and running repair, chaning app.cong files etc, SSG became connected again.
  • The main reason why I want to upgrade were some new features that were mentioned to be available in Dashboard Studio.

Unfortunately, now the present Dashboard Studio (version 1.15.3 under v9.3.2)  has some other issues, like: eg background color shows black instead of transparent (on mobile/table), big-font size 22+ text is unreadable small in Markdown (on mobile/tablet), using title color is  neither working as I expected...

Nb. besides the fact that also the new tab feature was already noted not to work in this version including next version  v9.4.0. so I understand. So here I close this post and will create a new post next year about Dashboard Studio. In the meantime waiting for an update to v9.4.X 

@all, have a great new year 2025!
AshleyP

0 Karma

apietersen
Contributor

I was able to install v9.3.2 without SSLEAY32.dll and LIBEAY32 .dll errors 

But now our Splunk Secure Gateways has stopped working 😞
Solving one issue and auto introduced to another issue 😞

Unable to initialize modular input "ssg_subscription_modular_input" defined in the app "splunk_secure_gateway": Introspecting scheme=ssg_subscription_modular_input: script running failed (exited with code 1)..11-12-2024, 10:03:22

apietersen_1-1733908698645.png

 

websocket: 
 Error in 'checkssgmobilewss' command: External search command exited unexpectedly with non-zero error code 1.

HTTPS(Sync): OK

HTTPS( Async):
Error in 'checkssgmobileasync' command: External search command exited unexpectedly with non-zero error code 1.

Does somebody has a suggestion what to do next? I am pretty much lost here, for the moment. 

AshleyP

0 Karma

apietersen
Contributor

This morning I did a repair on the v9.2.4 (with b9.2.4 of course) and tried to upgrade to v9.3.0 again
Validating install messages during the process, so nothing to worry about I thought??

At the end again: "code execution script cannot proceed SSLEAY32.dll was not found. Reinstalling the program may fix this problem" -

After this error it automatically starts a rollback, luckily, but I'm stuck on v9.2.4 now.

Questions:

  • What is a validating installation message, what is checked and what is not?
  • Can I view/look into this code somewhere to check if it points to the right directory
  • Is there a log file of the upgrade???

Has anyone had this problem before and/or does anyone know what I should do next? I am considering creating a support ticket.

Have done several upgrades over the years to our Splunk Enterprise platform but never experienced this. Any suggestion or tip is welcome.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @apietersen 

even I am seeing this for first time, howerver I would sugesst to try upgarde to 9.3.1 or 9.3.2 

and Under splunk-->var--->log--->splunk 
you can find migration log or splunkd.log  for any upagde realated errors 

apietersen
Contributor

Hi SanjayReddy,

Thanks for your response.

Looked in de logfile directory but could not find any file (or content in any files) that was referring to the upgrade !?

Ok, I will try to skip 9.3.0 and see what happens, in the coming days. 😨 I will post any results here.

Thanks 👍

0 Karma

apietersen
Contributor

Unfortunately , skipping 9.3.0 and tried to install v9.3.1, same result:

apietersen_0-1733684316463.png

apietersen_1-1733684370705.png

apietersen_2-1733684472912.png

I suppose, I need to create a ticket 😞

 

0 Karma

apietersen
Contributor
0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...
OSZAR »