Knowledge Management

(help) splunk is not work after restart server

lifekis
Explorer

I have mistake that deleted the configuration default file.
WebUI does not work properly after server restart.
What should I do?

deleted files
splunk/etc/apps/SplunkForwarder/*
splunk/etc/apps/SplunkLightForwarder/*
splunk/etc/apps/legacy/*
splunk/etc/apps/sample_app/*

 

KakaoTalk_20210219_161439874.jpg

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @lifekis,

it wasn't a good idea to delete some Splunk's default apps!

Anyway, you have three ways to restore your Splunk installation:

  • take the deleted files from a backup if present;
  • update Splunk to a following minor version (e.g. 8.1.1 to 8.1.2 or 7.3.3 to 7.3.4), if possible;
  • take the deleted folders and files from another installation of the same version of Splunk (if you haven't it, make a new installation in another server or in the same but in a different folder).

The first two solutions are prefereable because quicker, but I don't know if they are possible in your installation, the third requires more work but it runs.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @lifekis,

it wasn't a good idea to delete some Splunk's default apps!

Anyway, you have three ways to restore your Splunk installation:

  • take the deleted files from a backup if present;
  • update Splunk to a following minor version (e.g. 8.1.1 to 8.1.2 or 7.3.3 to 7.3.4), if possible;
  • take the deleted folders and files from another installation of the same version of Splunk (if you haven't it, make a new installation in another server or in the same but in a different folder).

The first two solutions are prefereable because quicker, but I don't know if they are possible in your installation, the third requires more work but it runs.

Ciao.

Giuseppe

lifekis
Explorer

It was solved using the third method. Thanks.

0 Karma

manjunathmeti
Champion

You can force upgrade Splunk to the same version again to restore default apps and files.

 

If this reply helps you, an upvote/like would be appreciated.

0 Karma

lifekis
Explorer

thanks, I will try.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...