Splunk Enterprise

Supervisor error

Kevin0202
Engager

I upgraded Splunk Enterprise to 10.0.0, but the supervisor is not running.

螢幕擷取畫面 2025-08-13 111456.png

Checked the server.conf the supervisor is enabled

[teleport_supervisor]
disabled = false

Search

index=_internal source=*supervisor.log*

 return empty result

Labels (1)
0 Karma

PrewinThomas
Motivator

@Kevin0202 
Can you see any errors with below,

index=_internal source=*splunkd.log* "*supervisor*"


Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

Kevin0202
Engager
index=_internal source=*splunkd.log* "*supervisor*"

Kevin0202_0-1755062767921.png

I now restore backup and upgrade it again.

There are supervisor logs this time.

Kevin0202_1-1755062863222.png

 

0 Karma

PrewinThomas
Motivator

@Kevin0202 
Can you check below,

-Is your Splunk running as root or a dedicated user?

-Check if any other process is bound to port 8194

netstat -anp | grep 8194

-Also check internal logs for any certificate error

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

Kevin0202
Engager

Kevin0202_0-1755067449741.png

I did not find any logs of certificate error related to supervisor or KVstore.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...