Splunk Enterprise

Need a hand. How is it possible to restart a UF/HF autom. when they stop working in the middle of the night / off hours?

SamHTexas
Builder

Is it possible to have a UF/HF automatically restarted when they stop working or not sending expected rate of events? There has been times the a UF went down / froze on Friday nights & we found out about it on Monday!! Appreciate your feed back.

Labels (1)
Tags (1)
0 Karma

burwell
SplunkTrust
SplunkTrust

You probably want to find out why the UF it's crashing. It is generally very robust. Are there errors that you can share? You can probably increase the logging level to help find what might be going wrong.

 

0 Karma

jcraumer
Explorer

If Unix is the OS it's possible to create a service for Splunk. Using MONIT you can monitor the running services and if it detects an abnormal shutdown it can be set up to restart the service and send email alerts for the admin team Ms. Burwell has a good point.  This will restart the Splunk instance but not identify why it's crashing so you could start a loop of crash/restarts.

For windows you can set up a batch file but you would needs to find a Monitoring service to handle watching the processes. 

SamHTexas
Builder

Thank u for your reply. Yes the OS is Linux RHEL (red hat). Would you share a re-start script for a standard re-start? Just for cases it shut down abnormally? Thank u

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...