Deployment Architecture

Restarting Splunk Agent when Home Directory is changed

_gkollias
Builder

I have some servers that don't comply to our newer Splunk Standards, and I'm doing a "Remediation" on the servers that need home directories changed, increased disk space, etc.

Will Splunkd need to be restarted after changing its home directory?

Thanks

Tags (3)
0 Karma
1 Solution

bandit
Motivator

If you are relocating the base install directory of Splunk on Unix, aka SPLUNK_HOME, then yes you would need to stop Splunk, relocate the directory, then start Splunk. On Unix, be sure, to update any boot script paths under /etc/init.d if you have enabled Splunk start on OS reboot.

If you are relocating on Windows, you would likely need to uninstall, then reinstall, first backing up the etc folder for configs you need to save.

View solution in original post

0 Karma

bandit
Motivator

Correct, that will work if running the forwarder as the root account. You'll need sudo or root permissions to run the command.

$SPLUNK_HOME/bin/splunk enable boot-start

If running as a non-root account i.e. splunk, then you'll need to use the -user switch to start it as that user.

$SPLUNK_HOME/bin/splunk enable boot-start -user splunk

0 Karma

bandit
Motivator

If you are relocating the base install directory of Splunk on Unix, aka SPLUNK_HOME, then yes you would need to stop Splunk, relocate the directory, then start Splunk. On Unix, be sure, to update any boot script paths under /etc/init.d if you have enabled Splunk start on OS reboot.

If you are relocating on Windows, you would likely need to uninstall, then reinstall, first backing up the etc folder for configs you need to save.

0 Karma

_gkollias
Builder

Thank you, Rob!

I also want to make sure the startup sequence is added. Is that simply $SPLUNK_HOME/bin/splunk enable boot-start?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...