Knowledge Management

(help) splunk is not work after restart server

lifekis
Explorer

I have mistake that deleted the configuration default file.
WebUI does not work properly after server restart.
What should I do?

deleted files
splunk/etc/apps/SplunkForwarder/*
splunk/etc/apps/SplunkLightForwarder/*
splunk/etc/apps/legacy/*
splunk/etc/apps/sample_app/*

 

KakaoTalk_20210219_161439874.jpg

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @lifekis,

it wasn't a good idea to delete some Splunk's default apps!

Anyway, you have three ways to restore your Splunk installation:

  • take the deleted files from a backup if present;
  • update Splunk to a following minor version (e.g. 8.1.1 to 8.1.2 or 7.3.3 to 7.3.4), if possible;
  • take the deleted folders and files from another installation of the same version of Splunk (if you haven't it, make a new installation in another server or in the same but in a different folder).

The first two solutions are prefereable because quicker, but I don't know if they are possible in your installation, the third requires more work but it runs.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @lifekis,

it wasn't a good idea to delete some Splunk's default apps!

Anyway, you have three ways to restore your Splunk installation:

  • take the deleted files from a backup if present;
  • update Splunk to a following minor version (e.g. 8.1.1 to 8.1.2 or 7.3.3 to 7.3.4), if possible;
  • take the deleted folders and files from another installation of the same version of Splunk (if you haven't it, make a new installation in another server or in the same but in a different folder).

The first two solutions are prefereable because quicker, but I don't know if they are possible in your installation, the third requires more work but it runs.

Ciao.

Giuseppe

lifekis
Explorer

It was solved using the third method. Thanks.

0 Karma

manjunathmeti
Champion

You can force upgrade Splunk to the same version again to restore default apps and files.

 

If this reply helps you, an upvote/like would be appreciated.

0 Karma

lifekis
Explorer

thanks, I will try.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...