Monitoring Splunk

splunkd service does not start when the server is rebooted

wendyctlam
Explorer

Hi,

I have a problem where splunkd services does not start at reboot of the server. The startup type is set to automatic. Can't find any error messages on this. Does anyone have any insight on this?

Wendy

Tags (1)

mhuang3
New Member

Does this mean "boot-start" is configured ?Thank you
alt text

0 Karma

mpaniagua_splun
Splunk Employee
Splunk Employee

Try this to find out more information about boot:

$SPLUNK_HOME/bin/splunk display boot-start

If this is the output:

Init script is not installed (checked: /etc/init.d/splunk).

Init script is not configured to run at boot.

Run this:

$SPLUNK_HOME/bin/splunk --enable boot-start

HTH.

srikanth1213
Path Finder

Hi ddrillic , any thoughts to resolve the issue on windows, in this scenario when "splunk display boot-start" command is giving you the correct output ..

0 Karma

srikanth1213
Path Finder

Hi, even we are facing the same issue but the output is fine when I run the command as shown below, can you please tell me by your exp what could be the cause for this. also we did setup the splunkd service startup type to be automatic.

E:\Program Files\Splunk\bin>splunk display boot-start
Windows services installed.
Windows services are configured to run at boot.

0 Karma

BenAveling
Path Finder

I think you mean ".../splunk enable boot-start"

And yes, I don't understand why this doesn't happen as part of the install - at the least it should be an option.

0 Karma

ddrillic
Ultra Champion

It needs root or sudo root permissions and therefore it's tricky to have it as part of the install (at least on linux).

0 Karma

mpaniagua_splun
Splunk Employee
Splunk Employee

Oh and for Windows this applies (taken from docs.splunk.com):

By default, Splunk starts automatically when you start your Windows machine. You can configure the Splunk processes (splunkd and splunkweb) to start manually from the Windows Services control panel.

0 Karma

TSTechJosh
Engager

Thank you for this response, it was exactly what I needed. I don't understand why this wasn't done as part of the install.

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...