Installation

what are the consequences of not running as bash on linux

yannK
Splunk Employee
Splunk Employee

I saw this article in the manual
http://docs.splunk.com/Documentation/Splunk/6.2.5/Installation/InstallonLinux#Default_shell

Default shell
Splunk Enterprise assumes you are using the bash shell.
Using the dash shell can result in zombie processes.

I am using ubuntu or debian, using dash as default, what would be the consequences ?

Tags (1)
1 Solution

yannK
Splunk Employee
Splunk Employee

The problem is that on "dash" shell, the processes created by splunk for scripted inputs will not be terminated when you restart splunk, or when the new script run starts.

By example with the AWS app, you may see many processes like

ps -aux | grep splunk
python /opt/splunk/etc/apps/Splunk_TA_aws/bin/aws_cloudwatch.py   

that will be running for a long time (even prior to the last splunk restart)
and ultimately exhaust resources on the box.

This does not happen since I run splunk under a bash shell.
Be careful on debian like OS (debian, and ubunbu)

View solution in original post

yannK
Splunk Employee
Splunk Employee

The problem is that on "dash" shell, the processes created by splunk for scripted inputs will not be terminated when you restart splunk, or when the new script run starts.

By example with the AWS app, you may see many processes like

ps -aux | grep splunk
python /opt/splunk/etc/apps/Splunk_TA_aws/bin/aws_cloudwatch.py   

that will be running for a long time (even prior to the last splunk restart)
and ultimately exhaust resources on the box.

This does not happen since I run splunk under a bash shell.
Be careful on debian like OS (debian, and ubunbu)

Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...