Splunk Enterprise

Why am I unable to start the splunk service?

skuma30
New Member

I tried to stop my splunk service, but it didn't work, so I killed the PID's so I can start splunk, but when I tried to start it later, it wouldn't start. When I entered splunk start, it is going a while with no output at all. It just hangs and there is nothing happening. Is there any solution for this that should be helpful for me?

0 Karma

mattymo
Splunk Employee
Splunk Employee

Why were u stopping splunk??

Any chance you were trying to enable ssl or install new certs??

- MattyMo
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi skuma30,
Which Splunk Version are you using and what Operative System?
I found the same problem on AIX 7.1 and I opened a case to Splunk Support.
There was a bug on all the versions available in december: 6.4.5, 6.5.1 and 6.3.8, that will be solved in the new minor releases of every Version.
I suggest to open a case to Splunk.
Bye.
Giuseppe

0 Karma

supabuck
Path Finder

Hello,

Try looking in splunkd.log. It contains information on what is occurring at the time which you are trying to start the service and while the service is running it will log events informing you of how it is running.

Lets say you have it installed in linux, the path would be $SPLUNK_HOME/var/log/splunk/splunkd.log

In the case of my personal instance I would use the following command to see what splunk is doing while it is starting up:

tail -f /opt/splunk/var/log/splunk/splunkd.log

Let us know what you find within this file.

Regards,
supabuck

0 Karma

skuma30
New Member

Here are the last logs of splunkd.

01-04-2017 19:34:57.551 +0000 ERROR TcpInputFd - SSL Error for fd from HOST:x, IP:x, PORT:51285
01-04-2017 19:35:57.605 +0000 ERROR TcpInputFd - SSL Error = error:1407609C:SSL routines:SSL23_GET_CLIENT_HELLO:http request
01-04-2017 19:35:57.605 +0000 ERROR TcpInputFd - ACCEPT_RESULT=-1 VERIFY_RESULT=0
01-04-2017 19:35:57.605 +0000 ERROR TcpInputFd - SSL Error for fd from HOST:x, IP:x, PORT:51709
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...