All Apps and Add-ons

Splunk on Splunk: Using the PS tool, what are the start and restart commands shown by all my Splunk systems in the SOS index?

hartfoml
Motivator

As I look in the SOS index i see all my 13 splunk systems showing a restart or start command to port 8089 like this;

splunkd -p_8089_restart

OR like this;

splunkd -p_8089_start

I have a suspicion that this is the command that that was given to start splunk so if I sent restart or start then that is what the process shows. Is that right?

Also I see some process commands like this;

splunkd -h_xxx.xxx.xxx.xxx_-p_8089_restart

Why do some start with the -h switch and some do not?

chanfoli
Builder

Splunkd is normally started by some invocation of $SPLUNK_HOME/bin/splunk, and I am thinking that you will see a start or restart option on the command in ps depending on how it was started. I am thinking that the -h parameter you are seeing is coming from an option in a stanza in a server.conf on one of your machines. I would look at server.conf(s) on the machine implicated by the value you see for -h or use btool on the system in question (which should also be the identified host value of an example event) to identify where this config item is coming from:

./splunk cmd btool server list --debug
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...