Monitoring Splunk

splunkd service does not start when the server is rebooted

wendyctlam
Explorer

Hi,

I have a problem where splunkd services does not start at reboot of the server. The startup type is set to automatic. Can't find any error messages on this. Does anyone have any insight on this?

Wendy

Tags (1)

mhuang3
New Member

Does this mean "boot-start" is configured ?Thank you
alt text

0 Karma

mpaniagua_splun
Splunk Employee
Splunk Employee

Try this to find out more information about boot:

$SPLUNK_HOME/bin/splunk display boot-start

If this is the output:

Init script is not installed (checked: /etc/init.d/splunk).

Init script is not configured to run at boot.

Run this:

$SPLUNK_HOME/bin/splunk --enable boot-start

HTH.

srikanth1213
Path Finder

Hi ddrillic , any thoughts to resolve the issue on windows, in this scenario when "splunk display boot-start" command is giving you the correct output ..

0 Karma

srikanth1213
Path Finder

Hi, even we are facing the same issue but the output is fine when I run the command as shown below, can you please tell me by your exp what could be the cause for this. also we did setup the splunkd service startup type to be automatic.

E:\Program Files\Splunk\bin>splunk display boot-start
Windows services installed.
Windows services are configured to run at boot.

0 Karma

BenAveling
Path Finder

I think you mean ".../splunk enable boot-start"

And yes, I don't understand why this doesn't happen as part of the install - at the least it should be an option.

0 Karma

ddrillic
Ultra Champion

It needs root or sudo root permissions and therefore it's tricky to have it as part of the install (at least on linux).

0 Karma

mpaniagua_splun
Splunk Employee
Splunk Employee

Oh and for Windows this applies (taken from docs.splunk.com):

By default, Splunk starts automatically when you start your Windows machine. You can configure the Splunk processes (splunkd and splunkweb) to start manually from the Windows Services control panel.

0 Karma

TSTechJosh
Engager

Thank you for this response, it was exactly what I needed. I don't understand why this wasn't done as part of the install.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...