Knowledge Management

Troubleshooting Splunk

mjlsnombrado
Communicator

Hi everyone

Can I ask for useful troubleshooting commands for example restart of services, licenses check, etc ?

Thanks in advance 🙂

0 Karma
1 Solution

vijithv
Explorer

Hi, the basic commands that help to start off splunk are,

splunk help - display usage summary

splunk help display the details of a specific object

splunk [start | stop | restart] - Start, stop and restart splunk
splunk start --accept-license - automatically accept the license without prompt
splunk status -display the splunk process status
splunk show splunkd-port - show the port that the splunkd listens on
splunk show web-port - show the port that splunk web listens on
splunk show servername - show the servername of this instance
splunk show default-hostname - show the default host name used for all data inputs

and this below link have the reference to CLI commands for troubleshooting
http://docs.splunk.com/Documentation/Splunk/7.0.3/Troubleshooting/CommandlinetoolsforusewithSupport

View solution in original post

0 Karma

vijithv
Explorer

Hi, the basic commands that help to start off splunk are,

splunk help - display usage summary

splunk help display the details of a specific object

splunk [start | stop | restart] - Start, stop and restart splunk
splunk start --accept-license - automatically accept the license without prompt
splunk status -display the splunk process status
splunk show splunkd-port - show the port that the splunkd listens on
splunk show web-port - show the port that splunk web listens on
splunk show servername - show the servername of this instance
splunk show default-hostname - show the default host name used for all data inputs

and this below link have the reference to CLI commands for troubleshooting
http://docs.splunk.com/Documentation/Splunk/7.0.3/Troubleshooting/CommandlinetoolsforusewithSupport

0 Karma

mjlsnombrado
Communicator

Thanks for the help 🙂

0 Karma

deepashri_123
Motivator

Hey@mjlsnombrado,

You can use btool command to check configuration files that are being used.
You can refer these documents for further reference:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Troubleshooting/Usebtooltotroubleshootconfiguratio...
http://docs.splunk.com/Documentation/Splunk/7.0.3/Troubleshooting/IntrototroubleshootingSplunk
Let me know if this helps!!

0 Karma

mjlsnombrado
Communicator

It helps thanks 🙂

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...