Getting Data In

Splunk list monitor, hanging

perfecto25
Path Finder

on the forwarder (centos 6.8), running 'splunk list monitor' simply hangs. No error msg or output,

[root@njo2/opt/splunkforwarder/etc/apps]# /opt/splunkforwarder/bin/splunk version
Splunk Universal Forwarder 6.5.1 (build f74036626f0c)

[root@njo2 /opt/splunkforwarder/etc/apps]# /opt/splunkforwarder/bin/splunk list monitor

..hangs

Im tryign to troubleshoot the forwarder, its not sending any log info to the indexer

Tags (3)
0 Karma

adonio
Ultra Champion

Hello perfecto25
first check if splunk is running /opt/splunkforwarder/bin/splunk status
i tested and splunk version command works when splunk is down but the list monitor command hangs
if its down, start splunk /opt/splunkforwarder/bin/splunk start
now when its up, run the list monitor command
hope it helps

0 Karma

perfecto25
Path Finder

yes, its running, still hangs, nothing in logs

[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk status
splunkd is running (PID: 15929).
splunk helpers are running (PIDs: 15937).
[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk list monitor

^C^
[root@njo1 /opt/splunkforwarder/var/log/splunk]#
[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk start
The splunk daemon (splunkd) is already running. [FAILED]

0 Karma

adonio
Ultra Champion

can you try and restart the forwarder?

0 Karma

perfecto25
Path Finder

tried that, no dice

All preliminary checks passed.

Starting splunk server daemon (splunkd)...

Done
[ OK ]
[root@njo1 /opt/splunkforwarder/var/log/splunk]# /opt/splunkforwarder/bin/splunk list monitor
...

0 Karma

adonio
Ultra Champion

very odd,
does the install of forwarder was smooth? does the forwarder version match the OS?
do you have any inputs configured already on forwarder?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...