Splunk Search

Issue with splunk stop/restart command in CentOS 7.2

keerthana_k
Communicator

Hi All,

Our distributed splunk setup contains a deployment server, an indexer cluster master, 3 peer indexers and 2 search heads. We use CentOS 7.2 for all our splunk instances and use salt stack to manage the nodes from a single point.

In our salt script, we use the command: service splunk stop/restart while installing or upgrading our apps. However, we find that this command works inconsistently. The command /opt/splunk/bin/splunk stop/restart works correctly.

Has anybody else faced this issue? Is this an issue specific to CentOS? Any pointers to this will be really helpful.

Thanks,
Keerthana

0 Karma

jonmargulies
Path Finder

The only potential issue I can think of is that "service splunk ..." requires elevated privileges while "/opt/splunk/bin/splunk ..." requires the privileges of whichever user owns /opt/splunk and its files. That's where I'd investigate first.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...