Monitoring Splunk

difference between splunkd and Splunkd service on Indexer

wfskmoney
Path Finder

We noticed we have 2 different processes running:

systemctl status splunk
systemctl status Splunkd

The docs explain that there are 2 ways to setup the Splunk service
https://docs.splunk.com/Documentation/Splunk/latest/Admin/RunSplunkassystemdservice#Unit_file_naming...

Is it correct that the 2 are running in parallel on the same machine? should it not be either one or the other?

Labels (1)
0 Karma

codebuilder
Influencer

This tells me that you have two Splunk process running under different users.
The daemon name is configured withing /opt/splunk/etc/splunk-launch.conf

You likely have one running from init.d (default) and another from systemd after configuring it.

Assuming this is not production, I would suggest that you try the following, in order:

/opt/splunk/bin/splunk stop
systemctl stop Splunkd
(here is where you can modify the daemon name in /opt/splunk/etc/splunk-launch.conf)
systemctl start Splunkd (or the name you set within the conf file)
----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...