Splunk Enterprise

Active: failed (Result: protocol)

Mahi4rus
Explorer

splunk@:~/bin $ systemctl status splunk
● splunkd.service - Splunk Universal Forwarder
Loaded: loaded (/etc/systemd/system/splunkd.service; enabled; vendor preset: disabled)
Active: failed (Result: protocol) since Tue 2021-04-20 11:49:25 UTC; 2h 41min ago
Process: 1869 ExecStart=/opt/splunkforwarder/bin/splunk start --accept-license --answer-yes --no-prompt (code=exited, status=0/SUCCESS)
Main PID: 2050 (code=exited, status=0/SUCCESS)

When i run the comand (systemctl status splunk) it will come like this i have kill the process and  and  restarted the splunk farwarder and its running now and i have removed the  all old PIDs.

can you please tell me how to resolve this issue. 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...