Deployment Architecture

Splunk Free: Why does the Splunk service disappear after some time and can no longer start it on an Ubuntu VM?

the4ndy
New Member

So I have been using the "free" 500mb version of Splunk at home for about 6 months now and I have had to reinstall Splunk at least 5 times. The reason....it disappears! I know this sounds crazy, I will qualify and explain as best I can.

I install Splunk onto a fresh Ubuntu VM and follow the instructions (which have changed over the past 6 months or so) provided on the website. After installation, everything works perfectly....I access the web interface, I add all my stuff and it works brilliantly. I monitor my logs for a month or so and then I leave it. It is just my home lab, so I do not check it daily (as I know I should), but if I leave it alone for too long, (I have not been able to pinpoint a time frame, but I went away camping for a little over a week, figure I didn't check 5 ish days on either end, so I'd say about 2 weeks at least) it stops working.

By not working / disappeared, I mean that the Splunk Web interface no longer answers. Splunk is installed on the VM, but there is no splunk service. I cannot run service splunk start and I can see very little traces of splunk other than it's installed (apt-get install splunk comes back already newest) and the only fix I have found is a reinstall (which loses all the data and configs). I have also tried the VM on multiple servers with various configurations in case it was some sort of hardware related issue...same result each time.

Is there something I am missing? I do not even know where to begin troubleshooting because it just seems that my problem is, Splunk just freaking disappeared on me, it got up, took half its stuff and vacated my server.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Does it "reappear" if you run this command?:

 /opt/splunk/bin/restart

If so, you havent set it to auto-start, and your computer is possibly restarting due to power failure, etc.

http://docs.splunk.com/Documentation/Splunk/6.0.8/admin/ConfigureSplunktostartatboottime

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...