Splunk Enterprise

Need a hand. How is it possible to restart a UF/HF autom. when they stop working in the middle of the night / off hours?

SamHTexas
Builder

Is it possible to have a UF/HF automatically restarted when they stop working or not sending expected rate of events? There has been times the a UF went down / froze on Friday nights & we found out about it on Monday!! Appreciate your feed back.

Labels (1)
Tags (1)
0 Karma

burwell
SplunkTrust
SplunkTrust

You probably want to find out why the UF it's crashing. It is generally very robust. Are there errors that you can share? You can probably increase the logging level to help find what might be going wrong.

 

0 Karma

jcraumer
Explorer

If Unix is the OS it's possible to create a service for Splunk. Using MONIT you can monitor the running services and if it detects an abnormal shutdown it can be set up to restart the service and send email alerts for the admin team Ms. Burwell has a good point.  This will restart the Splunk instance but not identify why it's crashing so you could start a loop of crash/restarts.

For windows you can set up a batch file but you would needs to find a Monitoring service to handle watching the processes. 

SamHTexas
Builder

Thank u for your reply. Yes the OS is Linux RHEL (red hat). Would you share a re-start script for a standard re-start? Just for cases it shut down abnormally? Thank u

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...