Install on MacOS
You can install Splunk Enterprise on macOS 10.15 and 10.14 with a DMG package or a .tgz file.
Splunk Enterprise is not supported on macOS 11. A forwarder installation package is available.
The macOS installation package comes in two forms: a DMG package and a .tgz file:
- If you require two installations in different locations on the same host, use the .tgz file. The DMG can only install Splunk Enterprise into the
- Navigate to the folder or directory where the installer is located.
- Double-click the DMG file.
A Finder window that contains the
- Double-click the
Install Splunkicon to start the installer.
- The Introduction panel lists version and copyright information. Click Continue.
- The License panel lists shows the software license agreement. Click Continue.
- You will be asked to agree to the terms of the software license agreement. Click Agree.
- In the Installation Type panel, click Install. This installs Splunk Enterprise in the default directory
- You are prompted to type the password that you use to login to your computer.
- When the installation finishes, a popup informs you that an initialization must be performed. Click OK.
- A terminal window appears and you are prompted to specify a userid and password to use with Splunk Enterprise.
The password must be at least 8 characters in length. The cursor will not advance as you type.
Make note of the userid and password. You will use these credentials to login Splunk Enterprise.
- A popup appears asking what you would like to do. Click Start and Show Splunk. The login page for Splunk Enterprise opens in your browser window.
- Close the Install Splunk window.
The installer places a shortcut on the Desktop so that you can launch Splunk Enterprise from your Desktop any time.
tar file install
Use the .tgz file to perform a manual installation of Splunk Enterprise. When you install Splunk Enterprise with the .tgz file:
- The service account is not created. If you want it to run Splunk Enterprise services with a specific user, you must create the user before starting the services.
- The default installation directory is the current working directory when you untar the .tgz file. The tar extraction will place all files in a
To install Splunk Enterprise on macOS:
- Place the <splunk_package_name.tgz> file into a folder.
- From the terminal, expand the tar file into the local directory using the
tar xvzf splunk_package_name.tgz
- Change directory to
Splunk/binand start the services.
Now that you have installed Splunk Enterprise:
- To start Splunk Enterprise services, see Start Splunk Enterprise for the first time.
- To configure Splunk Enterprise services to start at boot time, see Configure Splunk software to start at boot time in the Admin Manual.
- For more guidance on what to do, see What happens next?.
Are you looking for the universal forwarder installation?
The universal forwarder is a separate installation package, with its own installation procedures. To install a Splunk universal forwarder, see Install a *nix universal forwarder in the Universal Forwarder manual.
If you are upgrading a Splunk Enterprise instance, see How to upgrade Splunk Enterprise.
Uninstall Splunk Enterprise
If you want to remove Splunk Enterprise, see Uninstall Splunk Enterprise.
Install on Linux
Run Splunk Enterprise as a different or non-root user
This documentation applies to the following versions of Splunk® Enterprise: 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 9.0.0