Splunk Search

configuring splunk to start at boot time config file

aaronkorn
Splunk Employee
Splunk Employee

Is there a .conf file in splunk where you can configure splunk to start at boot time?

aholzer
Motivator

I don't believe it's a change in a splunk .conf file. When you run the CLI that several people mentioned below, it will make an entry into /etc/init.d I believe. That's where you'd have to check, but you can't roll something out via the deployment server to that location.

You may want to write a script that takes a list of hosts and runs the CLI on each host.

0 Karma

gfuente
Motivator

Hello

You can run this command from the splunk/bin folder:

./splunk enable boot-start -user splunk 

Or any other user you want splunk start with

Regards

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

Hello, I know there is a CLI command for it but we forgot to do this on a couple UF and would like to do a mass config change. We are just looking for a particular flag in a .conf file to set and push out.

0 Karma

phoffman_splunk
Splunk Employee
Splunk Employee
0 Karma

martin_mueller
SplunkTrust
SplunkTrust
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...