Hi I'm new to Splunk. I inherited Splunk from a past co-worker. I'm trying to log into Splunk, but can't get login form to show up. All the page says now is to download the latest Splunk version. Is this normal? I tried Googling and searching w/in the Splunk site but can't find the answer. I apologize in advanced if this is already answered. Thanks.
Very nice screenshot, your instance seems busted or customized to a very wicked level.
Are you using an enterprise splunk or a trial, or free version ?
Try the CLI commands to verify that this instance actually works. by example :
/opt/splunk/bin/splunk status
/opt/splunk/bin/splunk search "*"
To fix it apply maybe try an upgrade on it.
it will cause splunk to behave strangely for sure.
[root@....... ~]# df -h
Filesystem Size Used Avail Use% Mounted on
/dev/sda3 37G 37G 0 100% /
tmpfs 7.8G 0 7.8G 0% /dev/shm
/dev/sda1 485M 32M 428M 7% /boot
/dev/sdb1 996G 86G 861G 9% /data
Thanks. Looks like the root directory is completely full. I'm going to look into this.
[root@..... ~]# /opt/splunk/bin/splunk status
splunkd is not running.
splunkweb is running (PID: 1817).
[root@...... ~]# /opt/splunk/bin/splunk search "*"
CRIT - Error writing to "/opt/splunk/var/log/splunk/btool.log": No space left on device
Your session is invalid. Please login.
Splunk username:
Password:
Login failed
call not properly authenticated