<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;splunk restart&amp;quot; command takes long time in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/quot-splunk-restart-quot-command-takes-long-time/m-p/38446#M1072</link>
    <description>&lt;P&gt;I have found that stopping Splunk takes longer when there are searches running, especially realtime searches. My guess is that Splunk sends a "stop" to each running subprocess, and then waits a bit to allow them to stop gracefully.  How does that relate to your experience?  Do you have many users running searches?  Does Splunk stop faster if you exit the UI and do the stop command from the command line?&lt;/P&gt;</description>
    <pubDate>Wed, 21 Dec 2011 21:50:48 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2011-12-21T21:50:48Z</dc:date>
    <item>
      <title>"splunk restart" command takes long time</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/quot-splunk-restart-quot-command-takes-long-time/m-p/38444#M1070</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;When I issued "splunk restart" command, it takes more than 5 min.&lt;BR /&gt;
Looks like stopping splunk takes most of the restart time.&lt;/P&gt;

&lt;P&gt;Could you give us the possible reasons why restarting splunk takes longer time?&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2011 00:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/quot-splunk-restart-quot-command-takes-long-time/m-p/38444#M1070</guid>
      <dc:creator>melonman</dc:creator>
      <dc:date>2011-12-21T00:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: "splunk restart" command takes long time</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/quot-splunk-restart-quot-command-takes-long-time/m-p/38445#M1071</link>
      <description>&lt;P&gt;are there any errors displayed in the splunkd.log around the time of the shutdown? Might be worth installing the SoS app and using it to have a look at your internal logs for errors or warnings (perhaps even crashes on shutdown)&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2011 09:44:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/quot-splunk-restart-quot-command-takes-long-time/m-p/38445#M1071</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2011-12-21T09:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: "splunk restart" command takes long time</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/quot-splunk-restart-quot-command-takes-long-time/m-p/38446#M1072</link>
      <description>&lt;P&gt;I have found that stopping Splunk takes longer when there are searches running, especially realtime searches. My guess is that Splunk sends a "stop" to each running subprocess, and then waits a bit to allow them to stop gracefully.  How does that relate to your experience?  Do you have many users running searches?  Does Splunk stop faster if you exit the UI and do the stop command from the command line?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2011 21:50:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/quot-splunk-restart-quot-command-takes-long-time/m-p/38446#M1072</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2011-12-21T21:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: "splunk restart" command takes long time</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/quot-splunk-restart-quot-command-takes-long-time/m-p/38447#M1073</link>
      <description>&lt;P&gt;When you stop Splunk, it has to close out all the inputs, as well as the indexes and other components of the product. The more of these you've got floating around, the longer it takes. Splunkd.log  in $SPLUNK_HOME/var/log/splunk/ will tell you what is shutting down when the shutdown occurs. If your particularly curious what is taking so long, and you can't tell from splunkd.log, you can probably strace splunkd during the shutdown to see what is happening. For Windows, the equivalent tool would be procmon. I think you'll find the answer here. &lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2011 23:54:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/quot-splunk-restart-quot-command-takes-long-time/m-p/38447#M1073</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2011-12-21T23:54:06Z</dc:date>
    </item>
  </channel>
</rss>

