Getting Data In

Splunk list monitor, hanging

perfecto25
Path Finder

on the forwarder (centos 6.8), running 'splunk list monitor' simply hangs. No error msg or output,

[root@njo2/opt/splunkforwarder/etc/apps]# /opt/splunkforwarder/bin/splunk version
Splunk Universal Forwarder 6.5.1 (build f74036626f0c)

[root@njo2 /opt/splunkforwarder/etc/apps]# /opt/splunkforwarder/bin/splunk list monitor

..hangs

Im tryign to troubleshoot the forwarder, its not sending any log info to the indexer

Tags (3)
0 Karma

adonio
Ultra Champion

Hello perfecto25
first check if splunk is running /opt/splunkforwarder/bin/splunk status
i tested and splunk version command works when splunk is down but the list monitor command hangs
if its down, start splunk /opt/splunkforwarder/bin/splunk start
now when its up, run the list monitor command
hope it helps

0 Karma

perfecto25
Path Finder

yes, its running, still hangs, nothing in logs

[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk status
splunkd is running (PID: 15929).
splunk helpers are running (PIDs: 15937).
[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk list monitor

^C^
[root@njo1 /opt/splunkforwarder/var/log/splunk]#
[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk start
The splunk daemon (splunkd) is already running. [FAILED]

0 Karma

adonio
Ultra Champion

can you try and restart the forwarder?

0 Karma

perfecto25
Path Finder

tried that, no dice

All preliminary checks passed.

Starting splunk server daemon (splunkd)...

Done
[ OK ]
[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk list monitor
...

0 Karma

adonio
Ultra Champion

very odd,
does the install of forwarder was smooth? does the forwarder version match the OS?
do you have any inputs configured already on forwarder?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...