Splunk Enterprise

Restart of Splunk Agent using script

nvnbsibm
New Member

Hi All,

 

We are looking for a script to restart the splunk agent when ever it gets stopped could you please help us if anyone has any script to restart it on both linux & windows servers

 

THanks in Advance

Labels (1)
0 Karma

SinghK
Builder

On windows you don't need a script in services.msc there is an option for each sevice to recover if it stops there 3 actions u can define for first faliure second faliure and 3rd faliure. You can use that to auto restart and this can be pushed to all windows server as well as it's oob function in wimdows

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Firstly, if your forwarder crashes often, you should look for the cause.

Secondly - I'm not that proficient with windows services but with linux you can either use a solution that monitors and restarts service if needed if you're not using systemd (like monit). If you're using sysyemd, the unit file is written so that the service does restart in case of a crash. See https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/RunSplunkassystemdservice#Configure_systemd...

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

I totally agree with @PickleRick that if there are more than few crashes / stops on splunkd you should resolve the reason and fix it.

To restart splunkd in linux you should use systemd and in windows just configure service for restarting it after crash/stop. Then on both environment you should have some monitoring which are looking that those are running and if automation cannot restart those you must check those manually and find the reason why automation cannot bring services up.

r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...