Splunk Enterprise

Need a hand. How is it possible to restart a UF/HF autom. when they stop working in the middle of the night / off hours?

SamHTexas
Builder

Is it possible to have a UF/HF automatically restarted when they stop working or not sending expected rate of events? There has been times the a UF went down / froze on Friday nights & we found out about it on Monday!! Appreciate your feed back.

Labels (1)
Tags (1)
0 Karma

burwell
SplunkTrust
SplunkTrust

You probably want to find out why the UF it's crashing. It is generally very robust. Are there errors that you can share? You can probably increase the logging level to help find what might be going wrong.

 

0 Karma

jcraumer
Explorer

If Unix is the OS it's possible to create a service for Splunk. Using MONIT you can monitor the running services and if it detects an abnormal shutdown it can be set up to restart the service and send email alerts for the admin team Ms. Burwell has a good point.  This will restart the Splunk instance but not identify why it's crashing so you could start a loop of crash/restarts.

For windows you can set up a batch file but you would needs to find a Monitoring service to handle watching the processes. 

SamHTexas
Builder

Thank u for your reply. Yes the OS is Linux RHEL (red hat). Would you share a re-start script for a standard re-start? Just for cases it shut down abnormally? Thank u

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...