<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk processes in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-processes/m-p/59885#M11844</link>
    <description>&lt;P&gt;The first splunk process looks like the main one.&lt;/P&gt;

&lt;P&gt;You can take a look at the sos app (ta-sos) they have a script to monitor the splunk processes (ps-sos.sh for linux or ps-sos.ps1 for win)&lt;BR /&gt;
Then check the sos ressource dashboard, you will see the method used in the searches to distinguish the processes : &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;splunkd battleship&lt;/LI&gt;
&lt;LI&gt;splunkweb&lt;/LI&gt;
&lt;LI&gt;splunk searches&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 11 Dec 2012 16:31:45 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2012-12-11T16:31:45Z</dc:date>
    <item>
      <title>splunk processes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-processes/m-p/59884#M11843</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I want to add some monitoring to check that required splunk processes are running. On the indexer, I see the following:&lt;/P&gt;

&lt;P&gt;plunk    7481     1  9 Nov26 ?        1-10:34:49 splunkd -p 8089 start&lt;BR /&gt;
splunk    7482  7481  0 Nov26 ?        00:13:37 [splunkd pid=7481] splunkd -p 8089 start [process-runner]&lt;BR /&gt;
splunk    7639     1  0 Nov26 ?        00:59:43 python -O /apps/splunk/splunk/lib/python2.7/site-packages/splunk/appserver/mrsparkle/root.py start&lt;/P&gt;

&lt;P&gt;Which of these are required to be running?  I'm assuming pid 7481 - are the others required? Or do they spawn as needed? &lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2012 14:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-processes/m-p/59884#M11843</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2012-12-11T14:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: splunk processes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-processes/m-p/59885#M11844</link>
      <description>&lt;P&gt;The first splunk process looks like the main one.&lt;/P&gt;

&lt;P&gt;You can take a look at the sos app (ta-sos) they have a script to monitor the splunk processes (ps-sos.sh for linux or ps-sos.ps1 for win)&lt;BR /&gt;
Then check the sos ressource dashboard, you will see the method used in the searches to distinguish the processes : &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;splunkd battleship&lt;/LI&gt;
&lt;LI&gt;splunkweb&lt;/LI&gt;
&lt;LI&gt;splunk searches&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 11 Dec 2012 16:31:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-processes/m-p/59885#M11844</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-12-11T16:31:45Z</dc:date>
    </item>
  </channel>
</rss>

