Splunk Enterprise

Splunk Universal Forwarder not starting after rebooting

anh_nguyen
Explorer

I've tried to enable boot-start on *nix and Windows, but after the machine reboots, Splunk Forwarder still cannot start automatically. Can anyone have solutions for this case?

0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Base on this error message, it haven't removed /etc/init.d/splunk file. You should run again "disable" part and then check if that /etc/init.d/splunk file is there or not. If/when it's there, you must resolve the reason why it's here and remove it. Probably you have some hardening etc. on your system which cause this?

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Please tell us more.  Were you successful at enabling boot-start?  What command did you use?  Did you do so as root?  What errors are reported when the UF tries to start automatically?

---
If this reply helps you, Karma would be appreciated.
0 Karma

anh_nguyen
Explorer
  • For Ubuntu: I used the command 
[sudo] $SPLUNK_HOME/bin/splunk enable boot-start

But when i rebooted the machine, I check the status of splunk forwader by using command ./splunk status. It returned "splunkd is not running".

anh_nguyen_2-1697168942182.png

 

  • For Windows: according to Splunk document, Splunk will run automatically after startup. But after restarting the machine, i checked in the Task Manager, the SplunkForwarder was not running.

anh_nguyen_1-1697168789595.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

When you have run that command have you gotten any error/warnigs?

Have you try this?

sudo -uroot bash
$SPLUNK_HOME/bin/splunk enable boot-start -user splunk -systemd-managed 1

In current linux versions it's usually better to run splunk under systemd than old init.

But if you still want to use init then you must also update those startup scripts as this instructions said https://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/ConfigureSplunktostartatboottime

r. Ismo 

0 Karma

anh_nguyen
Explorer

I've tried the commands you suggested. But it still not work yet.

anh_nguyen_0-1697441813860.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Base on this error message, it haven't removed /etc/init.d/splunk file. You should run again "disable" part and then check if that /etc/init.d/splunk file is there or not. If/when it's there, you must resolve the reason why it's here and remove it. Probably you have some hardening etc. on your system which cause this?

anh_nguyen
Explorer

Finally, it works! Thank you very much.

SinghK
Builder

and for Ubuntu when you try to start it manually does it start or gives the same errors?

0 Karma

anh_nguyen
Explorer

when I try to start splunk by command "./splunk start", it starts normally

anh_nguyen_0-1697440963179.png

 

0 Karma

SinghK
Builder

for windows the service status should be set to automatic for it to start on boot.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...