Getting Data In

Light Forwarder for Linux - Autostart

beaunewcomb
Communicator

Is there a command line switch for the light forwarder (much like the one for splunkd) that will install the service in init.d for automatic starting with the server?

Tags (2)

Lowell
Super Champion

See the following docs page:

http://www.splunk.com/base/Documentation/latest/Admin/ConfigureSplunktostartatboottime


BTW, I do like to make a minor change to Splunk's default boot script that makes the startup work in a few extra situations. (For example, after a splunk upgrade)

By default, you'll see a line that looks like this (your's may be slightly different depending on what user splunkd is running as on your system, on mine the user is simply called "splunk"). This is in the splunk_start() function.

I change this line:

su splunk -c "\"$SPLUNK_HOME/bin/splunk\" start"

to the following:

su splunk -c "\"$SPLUNK_HOME/bin/splunk\" start --accept-license --answer-yes"

This ensures that any migration questions or license acceptance issues do not prevent splunk from starting up on an unattended boot. There are other startup options as well, but these are the two that I've found to work best for us.

Lowell
Super Champion

It's the same for both.

beaunewcomb
Communicator

Thanks for your response, but that's for the splunk server. I'm looking for the forwarder.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...