Getting Data In

Restarting Splunk with Scripted Input?

BenjaminWyatt
Communicator

Hi all,

   Here is the use case I'm dealing with. We have a large virtual environment in which a lot of teams like to just clone one VM to another, meaning that the forwarder hostname and guid gets cloned, which messes with our reporting. 

    I am trying to write a simple script that does the following:

1. Detects if a UF's hostname is correct or not

2. Runs a simple scripted input to clear out any cloned configs

3. Restarts the forwarder so that the new configs are picked up. 

    #3 is causing me trouble. If I try to put a "splunk restart" command in the main body of the script, then Splunk will stop, kill the scripted input, and never restart. I've also tried creating a "wrapper" script that invokes a separate script to do the restart, but with no success - Splunk will stop but not start back up. Is there a better way to do this? 

    All hosts are AWS Linux. 

Labels (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...