Installation

Splunkd is running after ./splunk stop command

marisstella
Explorer

Hii all,
I have created a copy of splunk instance, in the same server for testing purpose.. in this new splunk we will upgrade the version n check if the apps are working fine or not...
I copied some of the apps from old one to new splunk.. but here the issue is when i run ./splunk stop.. it only stopping SPLUNKWEB and SPLUNKD is running... But when i check it splunkweb is also running...
I don't whats happening...

Can as anybody tell me how to stop splunkd n splunkweb at a time??
Can you guys Guess my situation??

Labels (2)
0 Karma

sloshburch
Splunk Employee
Splunk Employee

If you copied Splunk while it was running then it probably copied the splunk.pid files. Therefore, when you try to stop splunk from the new copied version, it will think the old version's processes are it's own and try to stop them. Furthermore, you should be experiencing port conflicts.

I highly recommend you do not do such testing on the same machine. It will require a lot of extra work to ensure no port collisions and avoid these quirks. Copy Splunk to a new VM. This can be done with Docker, VirtualBox, cloud providers, etc...

0 Karma

sloshburch
Splunk Employee
Splunk Employee

What is showing you Splunk is still running?

0 Karma

nareshinsvu
Builder

Did you try stopping splunk using absolute path ? like

/opt/blah/blah/Splunk/bin/splunk stop

Check out this blog if it helps

https://wiki.splunk.com/Community:Run_multiple_Splunks_on_one_machine

0 Karma

marisstella
Explorer

Yes, I tried that.... splunk is still running only splunkweb stopped..

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...