Splunk Enterprise

Need a hand. How is it possible to restart a UF/HF autom. when they stop working in the middle of the night / off hours?

SamHTexas
Builder

Is it possible to have a UF/HF automatically restarted when they stop working or not sending expected rate of events? There has been times the a UF went down / froze on Friday nights & we found out about it on Monday!! Appreciate your feed back.

Labels (1)
Tags (1)
0 Karma

burwell
SplunkTrust
SplunkTrust

You probably want to find out why the UF it's crashing. It is generally very robust. Are there errors that you can share? You can probably increase the logging level to help find what might be going wrong.

 

0 Karma

jcraumer
Explorer

If Unix is the OS it's possible to create a service for Splunk. Using MONIT you can monitor the running services and if it detects an abnormal shutdown it can be set up to restart the service and send email alerts for the admin team Ms. Burwell has a good point.  This will restart the Splunk instance but not identify why it's crashing so you could start a loop of crash/restarts.

For windows you can set up a batch file but you would needs to find a Monitoring service to handle watching the processes. 

SamHTexas
Builder

Thank u for your reply. Yes the OS is Linux RHEL (red hat). Would you share a re-start script for a standard re-start? Just for cases it shut down abnormally? Thank u

Tags (1)
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>