Hello,
I have Universal Forward and Heavy Forward in Linux machine, how would I stop and restart them. Any help will be highly appreciated. Thank you so much, appreciate your support in these efforts.
@SplunkDash First of all for both UF & HF the process is same.
echo $SPLUNK_HOME
./splunk status
./splunk restart
./splunk start
That's all you need to do for a restart.
Also if this reply helped you a thumbs-up would be appreciated.
Remember that all solutions given here require that you run those commands as the user splunk is running with. You might run into problems if splunk have been running so far with its own user and you suddenly run it as root. Might cause some permissions problems later.
So it's advisable to start and stop the service using the normal system mechanisms:
systemctl start splunkd.service
systemctl stop splunkd.service
systemctl status sytemctl service
If you're running splunk on a distro that doesn't ship with systemd but with other init (is it still possible in 2021?), try your typical system services manipulation commands i.e. service splunkd start/stop.
@SplunkDash First of all for both UF & HF the process is same.
echo $SPLUNK_HOME
./splunk status
./splunk restart
./splunk start
That's all you need to do for a restart.
Also if this reply helped you a thumbs-up would be appreciated.
Hi,
The commands are the following:
- Stop Splunk: splunk stop
- Restart Splunk: splunk restart
You should be on the following path to execute the commands: $SPLUNK_HOME/bin/