Knowledge Management

(help) splunk is not work after restart server

lifekis
Explorer

I have mistake that deleted the configuration default file.
WebUI does not work properly after server restart.
What should I do?

deleted files
splunk/etc/apps/SplunkForwarder/*
splunk/etc/apps/SplunkLightForwarder/*
splunk/etc/apps/legacy/*
splunk/etc/apps/sample_app/*

 

KakaoTalk_20210219_161439874.jpg

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @lifekis,

it wasn't a good idea to delete some Splunk's default apps!

Anyway, you have three ways to restore your Splunk installation:

  • take the deleted files from a backup if present;
  • update Splunk to a following minor version (e.g. 8.1.1 to 8.1.2 or 7.3.3 to 7.3.4), if possible;
  • take the deleted folders and files from another installation of the same version of Splunk (if you haven't it, make a new installation in another server or in the same but in a different folder).

The first two solutions are prefereable because quicker, but I don't know if they are possible in your installation, the third requires more work but it runs.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @lifekis,

it wasn't a good idea to delete some Splunk's default apps!

Anyway, you have three ways to restore your Splunk installation:

  • take the deleted files from a backup if present;
  • update Splunk to a following minor version (e.g. 8.1.1 to 8.1.2 or 7.3.3 to 7.3.4), if possible;
  • take the deleted folders and files from another installation of the same version of Splunk (if you haven't it, make a new installation in another server or in the same but in a different folder).

The first two solutions are prefereable because quicker, but I don't know if they are possible in your installation, the third requires more work but it runs.

Ciao.

Giuseppe

lifekis
Explorer

It was solved using the third method. Thanks.

0 Karma

manjunathmeti
SplunkTrust
SplunkTrust

You can force upgrade Splunk to the same version again to restore default apps and files.

 

If this reply helps you, an upvote/like would be appreciated.

0 Karma

lifekis
Explorer

thanks, I will try.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...