<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk stop fails in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-stop-fails/m-p/54021#M7028</link>
    <description>&lt;P&gt;I have two splunk installation in this server. I see that both are running based on splunkd processed.  When I try to stop one of the (forwarder) it fails to stop.  No error messages anywhere that I can find.  Only a warning about splunk_home being set, which seems unrelated.&lt;/P&gt;

&lt;P&gt;any hints?&lt;/P&gt;

&lt;P&gt;-fdo&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sfdc@adhoc-app1-11-sfm bin]$ pwd
/home/sfdc/apps/splunk/prod-forwarder/bin
[sfdc@adhoc-app1-11-sfm bin]$ ps -efH | grep -B3 -A3 splunkd
root      5987     1  0 Mar23 ?        00:00:00   /usr/bin/python -tt /usr/sbin/yum-updatesd
root      6001     1  0 Mar23 ?        00:00:05   /usr/libexec/gam_server
root      6495     1  0 Mar23 ?        00:00:00   udevd
sfdc     21156     1 11 Nov29 ?        13:56:52   splunkd -p 42200 start
sfdc     21157 21156  0 Nov29 ?        00:01:23     splunkd -p 42200 start
sfdc      8566 21157  0 19:06 ?        00:00:01       splunkd search --id=1354647977.1740 --maxbuckets=0 --ttl=60 --maxout=500000 --maxtime=0 --lookups=1 --reduce_freq=10 --user=perfeng --pro --roles=admin:can_delete:corda_user:custcorelog:large_storage:mandm_team:power:searchrelevancy:splunk_admin:splunk_corda_user:splunk_delete:splunk_large_storage:splunk_mandm_dev:splunk_power_user:user
sfdc      8567  8566  0 19:06 ?        00:00:00         splunkd search --id=1354647977.1740 --maxbuckets=0 --ttl=60 --maxout=500000 --maxtime=0 --lookups=1 --reduce_freq=10 --user=perfeng --pro --roles=admin:can_delete:corda_user:custcorelog:large_storage:mandm_team:power:searchrelevancy:splunk_admin:splunk_corda_user:splunk_delete:splunk_large_storage:splunk_mandm_dev:splunk_power_user:user
sfdc     21212     1  0 Nov29 ?        00:14:53   python -O /home/sfdc/apps/splunk/prod-datacenter-1-indexer/lib/python2.6/site-packages/splunk/appserver/mrsparkle/root.py start
sfdc      8494     1  5 Dec01 ?        04:25:50   splunkd -p 9779 start
sfdc      8496  8494  0 Dec01 ?        00:00:00     splunkd -p 9779 start
[sfdc@adhoc-app1-11-sfm bin]$ ./splunk stop
Warning: overriding $SPLUNK_HOME setting in environment ("/home/sfdc/apps/splunk/prod-datacenter-1-indexer") with "/home/sfdc/apps/splunk/prod-forwarder".  If this is not correct, edit /home/sfdc/apps/splunk/prod-forwarder/etc/splunk-launch.conf
splunkweb is not running.
splunkd is not running.                                    [FAILED]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 04 Dec 2012 20:27:34 GMT</pubDate>
    <dc:creator>fcastano</dc:creator>
    <dc:date>2012-12-04T20:27:34Z</dc:date>
    <item>
      <title>splunk stop fails</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-stop-fails/m-p/54021#M7028</link>
      <description>&lt;P&gt;I have two splunk installation in this server. I see that both are running based on splunkd processed.  When I try to stop one of the (forwarder) it fails to stop.  No error messages anywhere that I can find.  Only a warning about splunk_home being set, which seems unrelated.&lt;/P&gt;

&lt;P&gt;any hints?&lt;/P&gt;

&lt;P&gt;-fdo&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sfdc@adhoc-app1-11-sfm bin]$ pwd
/home/sfdc/apps/splunk/prod-forwarder/bin
[sfdc@adhoc-app1-11-sfm bin]$ ps -efH | grep -B3 -A3 splunkd
root      5987     1  0 Mar23 ?        00:00:00   /usr/bin/python -tt /usr/sbin/yum-updatesd
root      6001     1  0 Mar23 ?        00:00:05   /usr/libexec/gam_server
root      6495     1  0 Mar23 ?        00:00:00   udevd
sfdc     21156     1 11 Nov29 ?        13:56:52   splunkd -p 42200 start
sfdc     21157 21156  0 Nov29 ?        00:01:23     splunkd -p 42200 start
sfdc      8566 21157  0 19:06 ?        00:00:01       splunkd search --id=1354647977.1740 --maxbuckets=0 --ttl=60 --maxout=500000 --maxtime=0 --lookups=1 --reduce_freq=10 --user=perfeng --pro --roles=admin:can_delete:corda_user:custcorelog:large_storage:mandm_team:power:searchrelevancy:splunk_admin:splunk_corda_user:splunk_delete:splunk_large_storage:splunk_mandm_dev:splunk_power_user:user
sfdc      8567  8566  0 19:06 ?        00:00:00         splunkd search --id=1354647977.1740 --maxbuckets=0 --ttl=60 --maxout=500000 --maxtime=0 --lookups=1 --reduce_freq=10 --user=perfeng --pro --roles=admin:can_delete:corda_user:custcorelog:large_storage:mandm_team:power:searchrelevancy:splunk_admin:splunk_corda_user:splunk_delete:splunk_large_storage:splunk_mandm_dev:splunk_power_user:user
sfdc     21212     1  0 Nov29 ?        00:14:53   python -O /home/sfdc/apps/splunk/prod-datacenter-1-indexer/lib/python2.6/site-packages/splunk/appserver/mrsparkle/root.py start
sfdc      8494     1  5 Dec01 ?        04:25:50   splunkd -p 9779 start
sfdc      8496  8494  0 Dec01 ?        00:00:00     splunkd -p 9779 start
[sfdc@adhoc-app1-11-sfm bin]$ ./splunk stop
Warning: overriding $SPLUNK_HOME setting in environment ("/home/sfdc/apps/splunk/prod-datacenter-1-indexer") with "/home/sfdc/apps/splunk/prod-forwarder".  If this is not correct, edit /home/sfdc/apps/splunk/prod-forwarder/etc/splunk-launch.conf
splunkweb is not running.
splunkd is not running.                                    [FAILED]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 04 Dec 2012 20:27:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunk-stop-fails/m-p/54021#M7028</guid>
      <dc:creator>fcastano</dc:creator>
      <dc:date>2012-12-04T20:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: splunk stop fails</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-stop-fails/m-p/54022#M7029</link>
      <description>&lt;P&gt;It looks like you are trying to stop the wrong splunk instance. The warning given shows you are overriding the &lt;CODE&gt;$SPLUNK_HOME&lt;/CODE&gt; variable, which is not the forwarder location.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;/home/sfdc/apps/splunk/prod-datacenter-1-indexer/bin/splunk stop&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2012 20:45:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunk-stop-fails/m-p/54022#M7029</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2012-12-04T20:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: splunk stop fails</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-stop-fails/m-p/54023#M7030</link>
      <description>&lt;P&gt;There are two instances of splunk running.  &lt;/P&gt;

&lt;P&gt;The indexer is running on port 42200. Because it has child processes that are running searches, that instance is the indexer. It is running as process id 21156 and subprocesses.&lt;/P&gt;

&lt;P&gt;The forwarder is running as process id 8494 on port 9779. It also has subprocesses.&lt;/P&gt;

&lt;P&gt;You have an environment variable (&lt;CODE&gt;$SPLUNK_HOME&lt;/CODE&gt;) set. The message that you get is simply pointing out that Splunk is ignoring the environment variable (which is good, because &lt;CODE&gt;$SPLUNK_HOME&lt;/CODE&gt; is pointing to the indexer, not the forwarder.)&lt;/P&gt;

&lt;P&gt;I would&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;su - sfdc
cd /home/sfdc/apps/splunk/prod-forwarder/bin
./splunk stop
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And if that didn't work, I would ensure that all files belong to &lt;CODE&gt;sfdc&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;chown -R sfdc /home/sfdc/apps/splunk/prod-forwarder
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and try again. Depending on the what the forwarder is monitoring, there might not be any big consequences to just killing the forwarder processes, but I consider this a last resort.&lt;/P&gt;

&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2012 21:44:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunk-stop-fails/m-p/54023#M7030</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-12-04T21:44:05Z</dc:date>
    </item>
  </channel>
</rss>

