Getting Data In

Splunk list monitor, hanging

perfecto25
Path Finder

on the forwarder (centos 6.8), running 'splunk list monitor' simply hangs. No error msg or output,

[root@njo2/opt/splunkforwarder/etc/apps]# /opt/splunkforwarder/bin/splunk version
Splunk Universal Forwarder 6.5.1 (build f74036626f0c)

[root@njo2 /opt/splunkforwarder/etc/apps]# /opt/splunkforwarder/bin/splunk list monitor

..hangs

Im tryign to troubleshoot the forwarder, its not sending any log info to the indexer

Tags (3)
0 Karma

adonio
Ultra Champion

Hello perfecto25
first check if splunk is running /opt/splunkforwarder/bin/splunk status
i tested and splunk version command works when splunk is down but the list monitor command hangs
if its down, start splunk /opt/splunkforwarder/bin/splunk start
now when its up, run the list monitor command
hope it helps

0 Karma

perfecto25
Path Finder

yes, its running, still hangs, nothing in logs

[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk status
splunkd is running (PID: 15929).
splunk helpers are running (PIDs: 15937).
[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk list monitor

^C^
[root@njo1 /opt/splunkforwarder/var/log/splunk]#
[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk start
The splunk daemon (splunkd) is already running. [FAILED]

0 Karma

adonio
Ultra Champion

can you try and restart the forwarder?

0 Karma

perfecto25
Path Finder

tried that, no dice

All preliminary checks passed.

Starting splunk server daemon (splunkd)...

Done
[ OK ]
[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk list monitor
...

0 Karma

adonio
Ultra Champion

very odd,
does the install of forwarder was smooth? does the forwarder version match the OS?
do you have any inputs configured already on forwarder?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...