All Apps and Add-ons

Splunk on Splunk: Using the PS tool, what are the start and restart commands shown by all my Splunk systems in the SOS index?

hartfoml
Motivator

As I look in the SOS index i see all my 13 splunk systems showing a restart or start command to port 8089 like this;

splunkd -p_8089_restart

OR like this;

splunkd -p_8089_start

I have a suspicion that this is the command that that was given to start splunk so if I sent restart or start then that is what the process shows. Is that right?

Also I see some process commands like this;

splunkd -h_xxx.xxx.xxx.xxx_-p_8089_restart

Why do some start with the -h switch and some do not?

chanfoli
Builder

Splunkd is normally started by some invocation of $SPLUNK_HOME/bin/splunk, and I am thinking that you will see a start or restart option on the command in ps depending on how it was started. I am thinking that the -h parameter you are seeing is coming from an option in a stanza in a server.conf on one of your machines. I would look at server.conf(s) on the machine implicated by the value you see for -h or use btool on the system in question (which should also be the identified host value of an example event) to identify where this config item is coming from:

./splunk cmd btool server list --debug
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...