Knowledge Management

(help) splunk is not work after restart server

lifekis
Explorer

I have mistake that deleted the configuration default file.
WebUI does not work properly after server restart.
What should I do?

deleted files
splunk/etc/apps/SplunkForwarder/*
splunk/etc/apps/SplunkLightForwarder/*
splunk/etc/apps/legacy/*
splunk/etc/apps/sample_app/*

 

KakaoTalk_20210219_161439874.jpg

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @lifekis,

it wasn't a good idea to delete some Splunk's default apps!

Anyway, you have three ways to restore your Splunk installation:

  • take the deleted files from a backup if present;
  • update Splunk to a following minor version (e.g. 8.1.1 to 8.1.2 or 7.3.3 to 7.3.4), if possible;
  • take the deleted folders and files from another installation of the same version of Splunk (if you haven't it, make a new installation in another server or in the same but in a different folder).

The first two solutions are prefereable because quicker, but I don't know if they are possible in your installation, the third requires more work but it runs.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @lifekis,

it wasn't a good idea to delete some Splunk's default apps!

Anyway, you have three ways to restore your Splunk installation:

  • take the deleted files from a backup if present;
  • update Splunk to a following minor version (e.g. 8.1.1 to 8.1.2 or 7.3.3 to 7.3.4), if possible;
  • take the deleted folders and files from another installation of the same version of Splunk (if you haven't it, make a new installation in another server or in the same but in a different folder).

The first two solutions are prefereable because quicker, but I don't know if they are possible in your installation, the third requires more work but it runs.

Ciao.

Giuseppe

lifekis
Explorer

It was solved using the third method. Thanks.

0 Karma

manjunathmeti
Champion

You can force upgrade Splunk to the same version again to restore default apps and files.

 

If this reply helps you, an upvote/like would be appreciated.

0 Karma

lifekis
Explorer

thanks, I will try.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...