Getting Data In

Scheduler not running?

bfeinberg
Engager

I am simply lost as to what is going on here. My splunk scheduler seems to have just stopped running. Restarting the services splunkd splunkweb seem to have no effect.

I looked at this wiki link and tried increasing the log level however nothing additional is shown

http://wiki.splunk.com/Community:TroubleshootingAlertScripts

In fact, no python.log is created, and scheduler.log has stopped being written to. I dont know how to proceed outside of reinstalling splunk, any thoughts?

Tags (1)

ww9rivers
Communicator

The question was posted so long ago, I don't know if a solution has already been found or no longer needed.

I just had the same problem when I tried to setup an alert with a scheduled saved search and it didn't work -- That led me to discover that the scheduler had completely stopped working for a while.

The cause in my case is that I setup the Splunk instance to be a dedicated search head, with the SplunkLightForwarder app enabled to forward data to the indexers. In enabling the light forwarder, its default/default-mode.conf file is activated and the stanza below is what disabled the scheduler:

# do not start the scheduler if in lwf mode
[pipeline:scheduler]
disabled_processors = LiveSplunks

Changing LiveSplunks to None has re-enabled the scheduler for me.

[edit]: I should say that I made a copy of the file in the light forwarder's local folder and changed the setting there. And that several Splunkers caution about changing the default-mode settings (http://docs.splunk.com/Documentation/Splunk/5.0.3/Deploy/Forwardercapabilities).

bfeinberg
Engager

No, I dont have a trial license, this is a full license of the software. General searches through the UI work properly and results are returned.

0 Karma

jonuwz
Influencer

Has your trial license expired ?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...