Knowledge Management

(help) splunk is not work after restart server

lifekis
Explorer

I have mistake that deleted the configuration default file.
WebUI does not work properly after server restart.
What should I do?

deleted files
splunk/etc/apps/SplunkForwarder/*
splunk/etc/apps/SplunkLightForwarder/*
splunk/etc/apps/legacy/*
splunk/etc/apps/sample_app/*

 

KakaoTalk_20210219_161439874.jpg

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @lifekis,

it wasn't a good idea to delete some Splunk's default apps!

Anyway, you have three ways to restore your Splunk installation:

  • take the deleted files from a backup if present;
  • update Splunk to a following minor version (e.g. 8.1.1 to 8.1.2 or 7.3.3 to 7.3.4), if possible;
  • take the deleted folders and files from another installation of the same version of Splunk (if you haven't it, make a new installation in another server or in the same but in a different folder).

The first two solutions are prefereable because quicker, but I don't know if they are possible in your installation, the third requires more work but it runs.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @lifekis,

it wasn't a good idea to delete some Splunk's default apps!

Anyway, you have three ways to restore your Splunk installation:

  • take the deleted files from a backup if present;
  • update Splunk to a following minor version (e.g. 8.1.1 to 8.1.2 or 7.3.3 to 7.3.4), if possible;
  • take the deleted folders and files from another installation of the same version of Splunk (if you haven't it, make a new installation in another server or in the same but in a different folder).

The first two solutions are prefereable because quicker, but I don't know if they are possible in your installation, the third requires more work but it runs.

Ciao.

Giuseppe

lifekis
Explorer

It was solved using the third method. Thanks.

0 Karma

manjunathmeti
Champion

You can force upgrade Splunk to the same version again to restore default apps and files.

 

If this reply helps you, an upvote/like would be appreciated.

0 Karma

lifekis
Explorer

thanks, I will try.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...