Monitoring Splunk

splunkd service does not start when the server is rebooted



I have a problem where splunkd services does not start at reboot of the server. The startup type is set to automatic. Can't find any error messages on this. Does anyone have any insight on this?


Tags (1)

New Member

Does this mean "boot-start" is configured ?Thank you
alt text

0 Karma

Splunk Employee
Splunk Employee

Try this to find out more information about boot:

$SPLUNK_HOME/bin/splunk display boot-start

If this is the output:

Init script is not installed (checked: /etc/init.d/splunk).

Init script is not configured to run at boot.

Run this:

$SPLUNK_HOME/bin/splunk --enable boot-start


Path Finder

Hi ddrillic , any thoughts to resolve the issue on windows, in this scenario when "splunk display boot-start" command is giving you the correct output ..

0 Karma

Path Finder

Hi, even we are facing the same issue but the output is fine when I run the command as shown below, can you please tell me by your exp what could be the cause for this. also we did setup the splunkd service startup type to be automatic.

E:\Program Files\Splunk\bin>splunk display boot-start
Windows services installed.
Windows services are configured to run at boot.

0 Karma

Path Finder

I think you mean ".../splunk enable boot-start"

And yes, I don't understand why this doesn't happen as part of the install - at the least it should be an option.

0 Karma

Ultra Champion

It needs root or sudo root permissions and therefore it's tricky to have it as part of the install (at least on linux).

0 Karma

Splunk Employee
Splunk Employee

Oh and for Windows this applies (taken from

By default, Splunk starts automatically when you start your Windows machine. You can configure the Splunk processes (splunkd and splunkweb) to start manually from the Windows Services control panel.

0 Karma


Thank you for this response, it was exactly what I needed. I don't understand why this wasn't done as part of the install.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...