Splunk Enterprise

How to run splunk forwarder on system startup

anil1432
Explorer

We have new servers in which we installed new Splunk forwarders that are running fine. In case of a system reboot, we would like to also start it up automatically. I noticed that our old servers has this file /etc/rc.d/init.d/splunk which is described in this guide

 https://docs.splunk.com/Documentation/Splunk/7.3.2/Admin/ConfigureSplunktostartatboottime

We don’t know who configured it for our old servers, but may I confirm that I need to follow the steps in the previous link and that I also need to be a root user to run splunk enable boot-start -user <preferred user>?.

 

Please can you give brief explanation and solutions please 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

New systems tend to use systemd to start processes at boot-time.  If yours does not then you can use your old init.d file; otherwise, run the enable boot-start command to have Splunk build a systemd startup file. 

Yes, you must be root to enable boot-start.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

New systems tend to use systemd to start processes at boot-time.  If yours does not then you can use your old init.d file; otherwise, run the enable boot-start command to have Splunk build a systemd startup file. 

Yes, you must be root to enable boot-start.

---
If this reply helps you, Karma would be appreciated.

anil1432
Explorer

Thank you very much . I got it .👍😊😊

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...