All Apps and Add-ons

"service streamfwd status" - Is There Documentation Listing What the Results of This Command Mean?


I'm looking for documentation on what the results of the "service streamfwd status" command. If this doc included the other parameters besides "status"; ie. stop/start/restart, that would be even better.

Also, looking for documentation on the statements listed when the streamfwd.log is viewed? If there is documentation for all .log files, that would be great as well.

If documentation is not available but someone is able to explain the below output (service streamfwd status), that will do for now.

● streamfwd.service - SYSV: Splunk Stream Forwarder 7.1.2
Loaded: loaded (/etc/rc.d/init.d/streamfwd; bad; vendor preset: disabled)
Active: active (running) since Thu 2018-09-13 15:10:01 EDT; 3 days ago
Docs: man:systemd-sysv-generator(8)
Process: 31736 ExecStart=/etc/rc.d/init.d/streamfwd start (code=exited, status=0/SUCCESS)
CGroup: /system.slice/streamfwd.service
└─31744 /opt/streamfwd/bin/streamfwd -D

Sep 13 15:10:01 stream1 systemd[1]: Starting SYSV: Splunk Stream Forwarder 7.1.2...
Sep 13 15:10:01 stream1 runuser[31741]: pam_unix(runuser:session): session opened for user streamfwd by (uid=0)
Sep 13 15:10:01 stream1 runuser[31741]: pam_unix(runuser:session): session closed for user streamfwd
Sep 13 15:10:01 stream1 streamfwd[31736]: Starting /opt/streamfwd/bin/streamfwd: [ OK ]
Sep 13 15:10:01 stream1 systemd[1]: Started SYSV: Splunk Stream Forwarder 7.1.2.

I'm particularly concerned with the bolded pieces of the output.

Thanks and God bless,

0 Karma

Splunk Employee
Splunk Employee

Hi. I ran your question by the stream dev team, and received this response:

The output of “service streamfwd start|stop|restart|status“ depends on the platform and also on the init system in use (Systemd, System V etc.). Typically, the output for the “service streamfwd status” is "streamfwd (pid) is running…" if streamfwd is running, or "streamfwd is stopped” if its not running. 
Here for this question,  I see this - "Active: active (running) since Thu 2018-09-13 15:10:01 EDT; 3 days ago” which means streamfwd is running.

I’ve filed a request to add some guidance to the Stream docs for using “service streamfwd start|stop|restart|status". For more info on the details of the output, you might also check some Linux-specific docs, such as this:

Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!