Monitoring Splunk

splunk process compulsion stop

kobayashikenji
Explorer

Hi

I want to kill the process of Splunk.
May be performed by specifying the "PID" with this command ?

kill -9 <PID>

There is no problem?

Tags (2)
0 Karma

miteshvohra
Contributor

You can kill all processes on 'splunkd' with

kill `ps -ef | grep splunkd | egrep -v grep | awk '{print $2}'`

But, just like @esix_splunk mentioned, make sure you restart Splunk with the correct user and that, using Splunk's native commands to Start/Stop/Restart the service is much cleaner.

Mitesh.

kobayashikenji
Explorer

Thank you very much.
I wanted absolutely compulsion stop.
Normally, you run the answer @ esix_splunk.

kenji.

0 Karma

miteshvohra
Contributor

@kobayashikenji I am bit curious to know about the purpose of force-stopping Splunk. 🙂

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

This works, make sure when you restart Splunk, you are using the correct user.

But why not do '/opt/splunk/splunk stop' or 'service splunk stop'

0 Karma

kobayashikenji
Explorer

If not stop at Splunk command,
Because I want to compulsion stop.
Normally, will use the "splunk stop".
Answer Thank you very much.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...