Getting Data In

Scheduler not running?

bfeinberg
Engager

I am simply lost as to what is going on here. My splunk scheduler seems to have just stopped running. Restarting the services splunkd splunkweb seem to have no effect.

I looked at this wiki link and tried increasing the log level however nothing additional is shown

http://wiki.splunk.com/Community:TroubleshootingAlertScripts

In fact, no python.log is created, and scheduler.log has stopped being written to. I dont know how to proceed outside of reinstalling splunk, any thoughts?

Tags (1)

ww9rivers
Contributor

The question was posted so long ago, I don't know if a solution has already been found or no longer needed.

I just had the same problem when I tried to setup an alert with a scheduled saved search and it didn't work -- That led me to discover that the scheduler had completely stopped working for a while.

The cause in my case is that I setup the Splunk instance to be a dedicated search head, with the SplunkLightForwarder app enabled to forward data to the indexers. In enabling the light forwarder, its default/default-mode.conf file is activated and the stanza below is what disabled the scheduler:

# do not start the scheduler if in lwf mode
[pipeline:scheduler]
disabled_processors = LiveSplunks

Changing LiveSplunks to None has re-enabled the scheduler for me.

[edit]: I should say that I made a copy of the file in the light forwarder's local folder and changed the setting there. And that several Splunkers caution about changing the default-mode settings (http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Forwardercapabilities).

bfeinberg
Engager

No, I dont have a trial license, this is a full license of the software. General searches through the UI work properly and results are returned.

0 Karma

jonuwz
Influencer

Has your trial license expired ?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...