Installation

what are the consequences of not running as bash on linux

yannK
Splunk Employee
Splunk Employee

I saw this article in the manual
http://docs.splunk.com/Documentation/Splunk/6.2.5/Installation/InstallonLinux#Default_shell

Default shell
Splunk Enterprise assumes you are using the bash shell.
Using the dash shell can result in zombie processes.

I am using ubuntu or debian, using dash as default, what would be the consequences ?

Tags (1)
1 Solution

yannK
Splunk Employee
Splunk Employee

The problem is that on "dash" shell, the processes created by splunk for scripted inputs will not be terminated when you restart splunk, or when the new script run starts.

By example with the AWS app, you may see many processes like

ps -aux | grep splunk
python /opt/splunk/etc/apps/Splunk_TA_aws/bin/aws_cloudwatch.py   

that will be running for a long time (even prior to the last splunk restart)
and ultimately exhaust resources on the box.

This does not happen since I run splunk under a bash shell.
Be careful on debian like OS (debian, and ubunbu)

View solution in original post

yannK
Splunk Employee
Splunk Employee

The problem is that on "dash" shell, the processes created by splunk for scripted inputs will not be terminated when you restart splunk, or when the new script run starts.

By example with the AWS app, you may see many processes like

ps -aux | grep splunk
python /opt/splunk/etc/apps/Splunk_TA_aws/bin/aws_cloudwatch.py   

that will be running for a long time (even prior to the last splunk restart)
and ultimately exhaust resources on the box.

This does not happen since I run splunk under a bash shell.
Be careful on debian like OS (debian, and ubunbu)

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...