When a SPLUNK server is rebooted, SPLUNK is cleanly shutdown
When SPLUNK vm is powered off, SPLUNK is cleanly shutdown
Hello,
I'm not certain on the exact search string but you could probably make use of your _internal index for this.
index=_internal log_level=ERROR OR log_level=WARN
Start with the above command and then look at the source=splunkd_stdout.log
and source=splunkd_stderr.log
to see if it found an existing PID file and had to remove it, etc. It will take some customization to your environment. Check this out:
http://docs.splunk.com/Documentation/Splunk/6.2.4/Troubleshooting/WhatSplunklogsaboutitself
Hello,
I'm not certain on the exact search string but you could probably make use of your _internal index for this.
index=_internal log_level=ERROR OR log_level=WARN
Start with the above command and then look at the source=splunkd_stdout.log
and source=splunkd_stderr.log
to see if it found an existing PID file and had to remove it, etc. It will take some customization to your environment. Check this out:
http://docs.splunk.com/Documentation/Splunk/6.2.4/Troubleshooting/WhatSplunklogsaboutitself