All Apps and Add-ons

Splunk will not start after installing sideview 2.4.10

DanielFordWA
Contributor

Hi,

I hope someone can help. I have installed sideview utils from the sideview website and was prompted to reboot splunk, however after 15 mins splunk had not rebooted.

I tried to start splunk from the command line, all checks pass but then splunk stops. (see below).

I have tried to look through the logs but I am not sure why this is happening, any advice would very helpful.

C:\Program Files\Splunk\bin>splunk start

Splunk> Map. Reduce. Recycle.

Checking prerequisites...
Checking http port [8000]: open
Checking mgmt port [8089]: open
Checking configuration... Done.
Checking indexes...
Validated databases: _audit _blocksignature _internal _thefishbu
cket history main sos sos_summary_daily summary
Done
Checking filesystem compatibility... Done
Checking conf files for typos... Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Splunkd: Stopped

--- And I see the below in the last few lines of my splunkd.log

I see the below in the last few lines of my splunkd.log

06-14-2013 09:52:24.720 +0100 INFO loader - Detected 4 (virtual) CPUs and 8191MB RAM

06-14-2013 09:52:24.720 +0100 INFO loader - Arguments are: "C:\Program Files\Splunk\bin\splunkd" "check-transforms-keys"

06-14-2013 09:52:24.720 +0100 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml

06-14-2013 09:52:24.720 +0100 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules

06-14-2013 09:52:24.720 +0100 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules

06-14-2013 09:52:24.720 +0100 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml

UPDATE - I have installed Splunk on my local machine and follow the same setup and installation process with the apps, Splunk works fine. The above is an instance of Splunk on a test server, is it possible installing apps in the UI or simply having the rights to restart the services may be lacking on my Dev server with my current credentials? Has anyone else experienced this?

1 Solution

DanielFordWA
Contributor

The account I was using lost rights to be used to login as service acct somehow for the splunk services, right resotred and Splunk is back up. 🙂

View solution in original post

DanielFordWA
Contributor

The account I was using lost rights to be used to login as service acct somehow for the splunk services, right resotred and Splunk is back up. 🙂

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...