Splunk Enterprise

Splunk Universal Forwarder not starting after rebooting

anh_nguyen
Explorer

I've tried to enable boot-start on *nix and Windows, but after the machine reboots, Splunk Forwarder still cannot start automatically. Can anyone have solutions for this case?

0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Base on this error message, it haven't removed /etc/init.d/splunk file. You should run again "disable" part and then check if that /etc/init.d/splunk file is there or not. If/when it's there, you must resolve the reason why it's here and remove it. Probably you have some hardening etc. on your system which cause this?

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Please tell us more.  Were you successful at enabling boot-start?  What command did you use?  Did you do so as root?  What errors are reported when the UF tries to start automatically?

---
If this reply helps you, Karma would be appreciated.
0 Karma

anh_nguyen
Explorer
  • For Ubuntu: I used the command 
[sudo] $SPLUNK_HOME/bin/splunk enable boot-start

But when i rebooted the machine, I check the status of splunk forwader by using command ./splunk status. It returned "splunkd is not running".

anh_nguyen_2-1697168942182.png

 

  • For Windows: according to Splunk document, Splunk will run automatically after startup. But after restarting the machine, i checked in the Task Manager, the SplunkForwarder was not running.

anh_nguyen_1-1697168789595.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

When you have run that command have you gotten any error/warnigs?

Have you try this?

sudo -uroot bash
$SPLUNK_HOME/bin/splunk enable boot-start -user splunk -systemd-managed 1

In current linux versions it's usually better to run splunk under systemd than old init.

But if you still want to use init then you must also update those startup scripts as this instructions said https://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/ConfigureSplunktostartatboottime

r. Ismo 

0 Karma

anh_nguyen
Explorer

I've tried the commands you suggested. But it still not work yet.

anh_nguyen_0-1697441813860.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Base on this error message, it haven't removed /etc/init.d/splunk file. You should run again "disable" part and then check if that /etc/init.d/splunk file is there or not. If/when it's there, you must resolve the reason why it's here and remove it. Probably you have some hardening etc. on your system which cause this?

anh_nguyen
Explorer

Finally, it works! Thank you very much.

SinghK
Builder

and for Ubuntu when you try to start it manually does it start or gives the same errors?

0 Karma

anh_nguyen
Explorer

when I try to start splunk by command "./splunk start", it starts normally

anh_nguyen_0-1697440963179.png

 

0 Karma

SinghK
Builder

for windows the service status should be set to automatic for it to start on boot.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...