Monitoring Splunk

How to troubleshoot why I am unable to start Splunk services (splunkd, splunkweb, splunkforwarder)?

sonia_splunk
New Member

Hello Everyone,

1) I had installed Splunk on Windows 2008 R2 a month ago.
2) Everything was good.
3) Today I have installed Splunk for SiteScope
4) Installed a forwarder on same server.
5) Added a few remote data sources
6) Firewall rules are configured correctly

Now I am unable to start Splunk services:
splunkd
splunkforwarder
splunkweb

All three services looks like in stuck state though they are showing started.
If I am trying to restart a service, it doesn't start instantly. I need to do 2 attempts.

Getting following error:

This page can’t be displayed

•Make sure the web address http://localhost:8000 is correct.
•Look for the page with your search engine.
•Refresh the page in a few minutes.

netstat -a command doesn't show port 8000.

My application stops working.

Thanks

Sonia

0 Karma

hortonew
Builder

I imagine installing the forwarder on the same server started the problems. By default, the forwarder and splunk enterprise will try to use port 8089 for management. You should look at changing the forwarder to use another port, or disable its rest endpoint via server.conf (disableDefaultPort = true).

On a side note, why are you running a forwarder on the same machine as your main splunk instance? Also what version of Splunk are you running?

0 Karma

sonia_splunk
New Member

Hi Hortonew,

Thanks for your reply.

I am learning Splunk.

I think, I have installed Splunk 6.x for Windows 2008 R2.

I have few questions.

I have installed Splunk on HP sitescope server.
Sitescope doesn't have very good reporting capability.
All required data is already available in SiteScope log files on same server.

I have also installed app Splunk for SiteScope.

So do I need to Install forwarder?

Where I will get Splunk - SiteScope integration guide.

Thanks

Sonia

0 Karma

hortonew
Builder

So on Windows 2008 you are running Splunk enterprise correct? The server. That should be the only thing running on that server. On your sitescope server, you should install the splunk universal forwarder to collect logs.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...