Splunk Enterprise

Error: Unable to stop splunk helpers.

jlaigo2
Path Finder

I have an indexer that froze and the server was rebooted. When I try to start, stop or even status splunk I get the following error. Has anyone run into this problem and has an answer?

[root@eulpol06 local]# /opt/splunk/bin/splunk stop
splunkd 25332 was not running.
Stopping splunk helpers...
still shutting down helpers...Timed out waiting for splunk helpers to stop. [FAILED]
Error: Unable to stop splunk helpers.
[root@eulpol06 local]#

Thanks,
Jaime

Tags (2)
1 Solution

Wiggy
Splunk Employee
Splunk Employee

When splunk is shut down improperly, sometimes it will leave behind a corrupted PID file in $SPLUNK_HOME/var/run/splunk directory and this error will show up when ./splunk start, restart or status is run.

The following steps should help resolve the issue:

  1. run ps -ef and make sure that Splunkd and Splunkweb are not running.
  2. Then move splunkd.pid and splunkweb.pid from $SPLUNK_HOME/var/run/splunk directory to a temporary directory.
  3. Then try running the command "./splunk status"

The error should no longer show up. After that try restarting and splunk should start up without the warning.

View solution in original post

golla
Engager

it worked . Thanks.

0 Karma

Padma12345
Explorer

It worked

0 Karma

YerlanTastambek
New Member

Thank you so much. really helped.

0 Karma

Wiggy
Splunk Employee
Splunk Employee

When splunk is shut down improperly, sometimes it will leave behind a corrupted PID file in $SPLUNK_HOME/var/run/splunk directory and this error will show up when ./splunk start, restart or status is run.

The following steps should help resolve the issue:

  1. run ps -ef and make sure that Splunkd and Splunkweb are not running.
  2. Then move splunkd.pid and splunkweb.pid from $SPLUNK_HOME/var/run/splunk directory to a temporary directory.
  3. Then try running the command "./splunk status"

The error should no longer show up. After that try restarting and splunk should start up without the warning.

Lorenzo1
Path Finder

so i found only splunkd.pib in my mac splunk folder but i couldn't move it to a temp directory so i moved it to trash. and even though the ./splunk status command couldn't run bcos it says "no such directory found"; it still worked. i was able to restart my Splunk Enterprise. Thanks guys.

0 Karma

Lorenzo1
Path Finder

hey bro,

i've done no.1

how do i process no. pls?

am using a mac. Thanxx for ur urgenbt assistance.

0 Karma

Trisha_Bayan30
New Member

Do we need to move again the splunkd.pid after we successfully restart?

0 Karma

sivakumarb
New Member

not required. After restart it will create new file with new PID

Tags (1)
0 Karma

srisplunk12
Engager

@wiggy :thanks a lot. . it did resolve the isssue..

0 Karma

nawazns5038
Builder

-bash-4.2$ /opt/splunk/bin/splunk restart
splunkd is not running. [FAILED]

But, I am getting the following error :

Splunk> Another one.

Checking prerequisites...
Checking http port [8443]: open
Checking mgmt port [8089]: already bound ERROR: The mgmt port
[8089] is already bound. Splunk needs
to use this port. Would you like to
change ports? [y/n]: n Exiting....

Please help !

0 Karma

season88481
Contributor

Thanks. I am in splunk 6.5 and I have the same problem.
There is no splunkweb.pid in my directory, so I just mv splunk.pid splunk.pid.bad. Then restart splunk, issue resolved!.

Thanks.

0 Karma

princemagaisa
New Member

this works

0 Karma

sk314
Builder

works like a charm! (for time travelers, splunk version 6.3.3)

0 Karma

_gkollias
SplunkTrust
SplunkTrust

Works like a charm. Thanks!

0 Karma

jlaigo2
Path Finder

Int the last 4yrs since posting this I figured it out.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...