Getting Data In

Scheduler not running?

bfeinberg
Engager

I am simply lost as to what is going on here. My splunk scheduler seems to have just stopped running. Restarting the services splunkd splunkweb seem to have no effect.

I looked at this wiki link and tried increasing the log level however nothing additional is shown

http://wiki.splunk.com/Community:TroubleshootingAlertScripts

In fact, no python.log is created, and scheduler.log has stopped being written to. I dont know how to proceed outside of reinstalling splunk, any thoughts?

Tags (1)

ww9rivers
Contributor

The question was posted so long ago, I don't know if a solution has already been found or no longer needed.

I just had the same problem when I tried to setup an alert with a scheduled saved search and it didn't work -- That led me to discover that the scheduler had completely stopped working for a while.

The cause in my case is that I setup the Splunk instance to be a dedicated search head, with the SplunkLightForwarder app enabled to forward data to the indexers. In enabling the light forwarder, its default/default-mode.conf file is activated and the stanza below is what disabled the scheduler:

# do not start the scheduler if in lwf mode
[pipeline:scheduler]
disabled_processors = LiveSplunks

Changing LiveSplunks to None has re-enabled the scheduler for me.

[edit]: I should say that I made a copy of the file in the light forwarder's local folder and changed the setting there. And that several Splunkers caution about changing the default-mode settings (http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Forwardercapabilities).

bfeinberg
Engager

No, I dont have a trial license, this is a full license of the software. General searches through the UI work properly and results are returned.

0 Karma

jonuwz
Influencer

Has your trial license expired ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...