Splunk Enterprise

Splunk Universal Forwarder not starting after rebooting

anh_nguyen
Explorer

I've tried to enable boot-start on *nix and Windows, but after the machine reboots, Splunk Forwarder still cannot start automatically. Can anyone have solutions for this case?

0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Base on this error message, it haven't removed /etc/init.d/splunk file. You should run again "disable" part and then check if that /etc/init.d/splunk file is there or not. If/when it's there, you must resolve the reason why it's here and remove it. Probably you have some hardening etc. on your system which cause this?

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Please tell us more.  Were you successful at enabling boot-start?  What command did you use?  Did you do so as root?  What errors are reported when the UF tries to start automatically?

---
If this reply helps you, Karma would be appreciated.
0 Karma

anh_nguyen
Explorer
  • For Ubuntu: I used the command 
[sudo] $SPLUNK_HOME/bin/splunk enable boot-start

But when i rebooted the machine, I check the status of splunk forwader by using command ./splunk status. It returned "splunkd is not running".

anh_nguyen_2-1697168942182.png

 

  • For Windows: according to Splunk document, Splunk will run automatically after startup. But after restarting the machine, i checked in the Task Manager, the SplunkForwarder was not running.

anh_nguyen_1-1697168789595.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

When you have run that command have you gotten any error/warnigs?

Have you try this?

sudo -uroot bash
$SPLUNK_HOME/bin/splunk enable boot-start -user splunk -systemd-managed 1

In current linux versions it's usually better to run splunk under systemd than old init.

But if you still want to use init then you must also update those startup scripts as this instructions said https://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/ConfigureSplunktostartatboottime

r. Ismo 

0 Karma

anh_nguyen
Explorer

I've tried the commands you suggested. But it still not work yet.

anh_nguyen_0-1697441813860.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Base on this error message, it haven't removed /etc/init.d/splunk file. You should run again "disable" part and then check if that /etc/init.d/splunk file is there or not. If/when it's there, you must resolve the reason why it's here and remove it. Probably you have some hardening etc. on your system which cause this?

anh_nguyen
Explorer

Finally, it works! Thank you very much.

SinghK
Builder

and for Ubuntu when you try to start it manually does it start or gives the same errors?

0 Karma

anh_nguyen
Explorer

when I try to start splunk by command "./splunk start", it starts normally

anh_nguyen_0-1697440963179.png

 

0 Karma

SinghK
Builder

for windows the service status should be set to automatic for it to start on boot.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...