<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunkd services are not starting on boot-start in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunkd-services-are-not-starting-on-boot-start/m-p/693618#M18005</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Hope this message finds you well.&lt;/P&gt;&lt;P&gt;I have installed splunk on-prem on a linux box as a splunk user and have given proper permissions.&lt;/P&gt;&lt;P&gt;The azure VM gets shutsdown automatically at around 11 pm everyday and there is no auto start. For time being we are manually starting the VM.&lt;/P&gt;&lt;P&gt;My problem here is while installing the splunk instance, I have run the command enable boot-start and it was successful but the splunkd services does not start on its own.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please suggest what can be done to fix it?&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jul 2024 14:38:25 GMT</pubDate>
    <dc:creator>man03359</dc:creator>
    <dc:date>2024-07-17T14:38:25Z</dc:date>
    <item>
      <title>Splunkd services are not starting on boot-start</title>
      <link>https://community.splunk.com/t5/Security/Splunkd-services-are-not-starting-on-boot-start/m-p/693618#M18005</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Hope this message finds you well.&lt;/P&gt;&lt;P&gt;I have installed splunk on-prem on a linux box as a splunk user and have given proper permissions.&lt;/P&gt;&lt;P&gt;The azure VM gets shutsdown automatically at around 11 pm everyday and there is no auto start. For time being we are manually starting the VM.&lt;/P&gt;&lt;P&gt;My problem here is while installing the splunk instance, I have run the command enable boot-start and it was successful but the splunkd services does not start on its own.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please suggest what can be done to fix it?&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 14:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkd-services-are-not-starting-on-boot-start/m-p/693618#M18005</guid>
      <dc:creator>man03359</dc:creator>
      <dc:date>2024-07-17T14:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd services are not starting on boot-start</title>
      <link>https://community.splunk.com/t5/Security/Splunkd-services-are-not-starting-on-boot-start/m-p/693644#M18006</link>
      <description>&lt;P&gt;So there are a lot of questions to ask, as you state just linux. Is it debian or centos/redhat based? If it's redhat, are you using systemd?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.2/Admin/ConfigureSplunktostartatboottime" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.2/Admin/ConfigureSplunktostartatboottime&lt;/A&gt;&lt;/P&gt;&lt;P&gt;When you run&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;[sudo] $SPLUNK_HOME/bin/splunk enable boot-start -user splunk&lt;/PRE&gt;&lt;P&gt;what sort of output do you get?&lt;/P&gt;&lt;P&gt;Keep in mind if you are using systemd there is an &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.2/Admin/ConfigureSplunktostartatboottime#Enable_boot-start_on_machines_that_run_systemd" target="_blank" rel="noopener"&gt;entire section&lt;/A&gt; in the documentation that goes over fighting that lovely beast.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you checked /opt/splunk/var/log/splunk/splunkd.log to see if there are any issues with it attempting to autostart? Sometimes things such as permissions issues can also affect it. Are you able to manually start splunk as the splunk user and it boots up fine?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 22:21:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkd-services-are-not-starting-on-boot-start/m-p/693644#M18006</guid>
      <dc:creator>TheLawsOfChaos</dc:creator>
      <dc:date>2024-07-17T22:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd services are not starting on boot-start</title>
      <link>https://community.splunk.com/t5/Security/Splunkd-services-are-not-starting-on-boot-start/m-p/693674#M18007</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49853"&gt;@TheLawsOfChaos&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The Linux is a redhad.&lt;/P&gt;&lt;P&gt;And I have already created&amp;nbsp; a user called splunk, so under this path -&lt;/P&gt;&lt;PRE&gt;cd /opt/splunk/bin/&lt;/PRE&gt;&lt;P&gt;I am running this command -&lt;/P&gt;&lt;P&gt;sudo ./splunk enable boot-start.&lt;/P&gt;&lt;P&gt;I am able to manually start the services using-&lt;/P&gt;&lt;P&gt;sudo ./splunk start&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 07:10:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkd-services-are-not-starting-on-boot-start/m-p/693674#M18007</guid>
      <dc:creator>man03359</dc:creator>
      <dc:date>2024-07-18T07:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd services are not starting on boot-start</title>
      <link>https://community.splunk.com/t5/Security/Splunkd-services-are-not-starting-on-boot-start/m-p/693816#M18010</link>
      <description>&lt;P&gt;So when running the Splunk service, you do not want to be running it as root (which is primarily what sudo does). Since you have run some of the commands via sudo, that means some of the file permissions most likely were changed to root owning it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would want to follow these steps:&lt;/P&gt;&lt;P&gt;First, you need to ensure that the splunk user/group owns the files, since you have been running it as root (sudo)&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;sudo chown -R splunk:splunk /opt/splunk&lt;/LI-CODE&gt;&lt;P&gt;Second, you want to become the splunk user&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;sudo su splunk&lt;/LI-CODE&gt;&lt;P&gt;Then you want to run your commands as normal&lt;/P&gt;&lt;P&gt;3)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;./splunk enable boot-start -user splunk&lt;/LI-CODE&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;./splunk enable boot-start -user splunk -systemd-managed 1&lt;/LI-CODE&gt;&lt;P&gt;if you are using systems on your system.&lt;/P&gt;&lt;P&gt;By running the commands as the splunk user, you ensure that the splunk user maintains ownership over /opt/splunk, and that means that the enable boot start will be able to work. I think if you checked your linux logs, you would see during boot up there are probably permission errors stating that the user splunk does not have access to the /opt/splunk folder, due to the sudo issues.&lt;/P&gt;&lt;P&gt;After doing this, while still as the splunk user you can run ./splunk start.&lt;/P&gt;&lt;P&gt;If you don't want to do sudo su splunk, to become the user you can use something like this instead:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;sudo -H -u splunk $SPLUNK_HOME/bin/splunk start&lt;/LI-CODE&gt;&lt;P&gt;This will let you use sudo as your user, tell it to act as the splunk user, and then start splunk. This method of sudo usage could replace directly sudo su splunk if needed.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 04:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkd-services-are-not-starting-on-boot-start/m-p/693816#M18010</guid>
      <dc:creator>TheLawsOfChaos</dc:creator>
      <dc:date>2024-07-19T04:10:37Z</dc:date>
    </item>
  </channel>
</rss>

