Splunk Enterprise

Error: Unable to stop splunk helpers.

jlaigo2
Path Finder

I have an indexer that froze and the server was rebooted. When I try to start, stop or even status splunk I get the following error. Has anyone run into this problem and has an answer?

[root@eulpol06 local]# /opt/splunk/bin/splunk stop
splunkd 25332 was not running.
Stopping splunk helpers...
still shutting down helpers...Timed out waiting for splunk helpers to stop. [FAILED]
Error: Unable to stop splunk helpers.
[root@eulpol06 local]#

Thanks,
Jaime

Tags (2)
1 Solution

Wiggy
Splunk Employee
Splunk Employee

When splunk is shut down improperly, sometimes it will leave behind a corrupted PID file in $SPLUNK_HOME/var/run/splunk directory and this error will show up when ./splunk start, restart or status is run.

The following steps should help resolve the issue:

  1. run ps -ef and make sure that Splunkd and Splunkweb are not running.
  2. Then move splunkd.pid and splunkweb.pid from $SPLUNK_HOME/var/run/splunk directory to a temporary directory.
  3. Then try running the command "./splunk status"

The error should no longer show up. After that try restarting and splunk should start up without the warning.

View solution in original post

golla
Engager

it worked . Thanks.

0 Karma

Padma12345
Explorer

It worked

0 Karma

YerlanTastambek
New Member

Thank you so much. really helped.

0 Karma

Wiggy
Splunk Employee
Splunk Employee

When splunk is shut down improperly, sometimes it will leave behind a corrupted PID file in $SPLUNK_HOME/var/run/splunk directory and this error will show up when ./splunk start, restart or status is run.

The following steps should help resolve the issue:

  1. run ps -ef and make sure that Splunkd and Splunkweb are not running.
  2. Then move splunkd.pid and splunkweb.pid from $SPLUNK_HOME/var/run/splunk directory to a temporary directory.
  3. Then try running the command "./splunk status"

The error should no longer show up. After that try restarting and splunk should start up without the warning.

Lorenzo1
Path Finder

so i found only splunkd.pib in my mac splunk folder but i couldn't move it to a temp directory so i moved it to trash. and even though the ./splunk status command couldn't run bcos it says "no such directory found"; it still worked. i was able to restart my Splunk Enterprise. Thanks guys.

0 Karma

Lorenzo1
Path Finder

hey bro,

i've done no.1

how do i process no. pls?

am using a mac. Thanxx for ur urgenbt assistance.

0 Karma

Trisha_Bayan30
New Member

Do we need to move again the splunkd.pid after we successfully restart?

0 Karma

sivakumarb
New Member

not required. After restart it will create new file with new PID

Tags (1)
0 Karma

srisplunk12
Engager

@wiggy :thanks a lot. . it did resolve the isssue..

0 Karma

nawazns5038
Builder

-bash-4.2$ /opt/splunk/bin/splunk restart
splunkd is not running. [FAILED]

But, I am getting the following error :

Splunk> Another one.

Checking prerequisites...
Checking http port [8443]: open
Checking mgmt port [8089]: already bound ERROR: The mgmt port
[8089] is already bound. Splunk needs
to use this port. Would you like to
change ports? [y/n]: n Exiting....

Please help !

0 Karma

season88481
Contributor

Thanks. I am in splunk 6.5 and I have the same problem.
There is no splunkweb.pid in my directory, so I just mv splunk.pid splunk.pid.bad. Then restart splunk, issue resolved!.

Thanks.

0 Karma

princemagaisa
New Member

this works

0 Karma

sk314
Builder

works like a charm! (for time travelers, splunk version 6.3.3)

0 Karma

_gkollias
Builder

Works like a charm. Thanks!

0 Karma

jlaigo2
Path Finder

Int the last 4yrs since posting this I figured it out.

0 Karma
Get Updates on the Splunk Community!

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...