Security
Highlighted

How to restart splunkweb? Getting error "Permission denied splunkd.pid is unreadable"

Explorer

We have an issue with splunkweb services unable to run them. Can anyone help resolving this error?

Splunk status:
Pid file "/opt/splunk/var/run/splunk/splunkd.pid" unreadable.: Permission denied
splunkd.pid file is unreadable.
splunkweb is not running.
Pid file "/opt/splunk/var/run/splunk/splunkd.pid" unreadable.: Permission denied
0 Karma
Highlighted

Re: How to restart splunkweb? Getting error "Permission denied splunkd.pid is unreadable"

Splunk Employee
Splunk Employee

Try running this as the actual user running Splunk. Sounds like you have a "we'd prefer to run as user but Splunk got started as 'root'" situation.

0 Karma
Highlighted

Re: How to restart splunkweb? Getting error "Permission denied splunkd.pid is unreadable"

Explorer

Hi Sowings ,

I have restarted splunkweb services in all the server instances , everythng are running fine in the server . but im unable to load the splunk web page its throwing me error.

Will it be any problem with network side.

0 Karma
Highlighted

Re: How to restart splunkweb? Getting error "Permission denied splunkd.pid is unreadable"

Motivator

No it seems splunk has not started successfully. Check the ./splunk status. Verify the splunkd.log file for any error that your are getting.

0 Karma
Highlighted

Re: How to restart splunkweb? Getting error "Permission denied splunkd.pid is unreadable"

Explorer

i have verified splunkd.log , i cant find any error related with host and check whether ports are listening or not every where i can see
splunkd 3567 root 4u IPv4 2234532 0t0 TCP *:8089 (LISTEN)

and i check ./splunk status

splunkd is running (PID: 3567).
splunk helpers are running (PIDs: 3568).
splunkweb is running (PID: 3632).

still unable to understand why i cant get into the page

0 Karma
Highlighted

Re: How to restart splunkweb? Getting error "Permission denied splunkd.pid is unreadable"

SplunkTrust
SplunkTrust

I bet Splunk is started by root. You should check that out

%SPLUNK/bin

0 Karma