<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error message when creating new Splunk instance: The splunk daemon (splunkd) is already running. [FAILED] in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321670#M2969</link>
    <description>&lt;P&gt;Hi, splunk-launch.conf did the trick, thanks for your help.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Oct 2017 14:51:26 GMT</pubDate>
    <dc:creator>jackiewkc</dc:creator>
    <dc:date>2017-10-23T14:51:26Z</dc:date>
    <item>
      <title>Error message when creating new Splunk instance: The splunk daemon (splunkd) is already running. [FAILED]</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321666#M2965</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am running a splunk instance on a server under /apps/splunk-1/ at port 8980. I would like to run another instance on the same server at a different port. So I ran "cp -R /app/splunk-1 /apps/splunk-2" to create a new instance. Then I removed the pid file under /apps/splunk-2/var/run, updated the related files so that it will use a different port (8950). &lt;/P&gt;

&lt;P&gt;However, when I ran "/apps/splunk-2/bin/splunk start", I got the following error:&lt;/P&gt;

&lt;P&gt;The splunk daemon (splunkd) is already running. [FAILED]&lt;/P&gt;

&lt;P&gt;If you get stuck, we're here to help.&lt;BR /&gt;
Look for answers here: &lt;A href="http://docs.splunk.com"&gt;http://docs.splunk.com&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The Splunk web interface is at &lt;A href="http://server1:8980"&gt;http://server1:8980&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;When I executed /apps/splunk-2/bin/splunk status, I got this:&lt;/P&gt;

&lt;P&gt;splunkd is running (PID: 3898).&lt;BR /&gt;
splunk helpers are running (PIDs: 3903 4024 4060 4083).&lt;/P&gt;

&lt;P&gt;Can someone please advise why splunk-2 is still referencing splunk-1?&lt;/P&gt;

&lt;P&gt;What else do I need to update under splunk-2?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Jackie&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 12:12:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321666#M2965</guid>
      <dc:creator>jackiewkc</dc:creator>
      <dc:date>2017-10-23T12:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Error message when creating new Splunk instance: The splunk daemon (splunkd) is already running. [FAILED]</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321667#M2966</link>
      <description>&lt;P&gt;Check the following configuration files, they should be located in the &lt;STRONG&gt;/app/splunk-2/etc/system/local&lt;/STRONG&gt; :&lt;/P&gt;

&lt;P&gt;instance.cfg : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Instancecfgconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Instancecfgconf&lt;/A&gt;&lt;BR /&gt;
web.conf : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Webconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Webconf&lt;/A&gt;&lt;BR /&gt;
inputs.conf : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Inputsconf&lt;/A&gt;&lt;BR /&gt;
server.conf : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Serverconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Serverconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You'll need to update the configurations, change the ports, GUID, instance name, and any other specific configuration items you might have copied over. After that, I'd run a killall splunkd and killall mongod to make sure all the processes are killed. From there, you can run &lt;STRONG&gt;/opt/splunk-1/bin/splunk start&lt;/STRONG&gt; and &lt;STRONG&gt;/opt/splunk-2/bin/splunk start&lt;/STRONG&gt;. &lt;/P&gt;

&lt;P&gt;You should be careful about the run-as user and permissions associated with each running Splunk instance....&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 12:27:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321667#M2966</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2017-10-23T12:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Error message when creating new Splunk instance: The splunk daemon (splunkd) is already running. [FAILED]</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321668#M2967</link>
      <description>&lt;P&gt;Hi, thanks for the information. I have updated all those files already. Under /apps/splunk-2/etc/system/local, I ran "grep -ir 8980 ." to confirm that there is no reference to the port used by splunk-1.&lt;/P&gt;

&lt;P&gt;Can you please advise how ./splunk start and ./splunk status work? i.e. where do they look for the related configs?&lt;/P&gt;

&lt;P&gt;/apps/splunk-2/bin/splunk status still references splunk-1 so it must look at somewhere to get the port, pid file, the name of the instance or something else to check the status, right?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Jackie&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 12:32:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321668#M2967</guid>
      <dc:creator>jackiewkc</dc:creator>
      <dc:date>2017-10-23T12:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: Error message when creating new Splunk instance: The splunk daemon (splunkd) is already running. [FAILED]</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321669#M2968</link>
      <description>&lt;P&gt;How are you starting and stopping Splunk?&lt;/P&gt;

&lt;P&gt;Additional, check out your splunk-launch.conf file : &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/Splunk-launchconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/Splunk-launchconf&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Make sure your referrences are in there properly. These are configured in the initial installation. &lt;/P&gt;

&lt;P&gt;Alternatively, you should just install a fresh copy of Splunk in /opt/splunk-2. Download the tarball and extract it to there.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 12:38:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321669#M2968</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2017-10-23T12:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: Error message when creating new Splunk instance: The splunk daemon (splunkd) is already running. [FAILED]</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321670#M2969</link>
      <description>&lt;P&gt;Hi, splunk-launch.conf did the trick, thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 14:51:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-message-when-creating-new-Splunk-instance-The-splunk/m-p/321670#M2969</guid>
      <dc:creator>jackiewkc</dc:creator>
      <dc:date>2017-10-23T14:51:26Z</dc:date>
    </item>
  </channel>
</rss>

