Monitoring Splunk

After my certificates expired and I followed the steps in documentation for getting third party certificates, why is splunkd not starting?

apentaros
Engager

My certificates expired recently and I did the procedures in this article :

http://docs.splunk.com/Documentation/Splunk/6.2.2/Security/Howtogetthird-partycertificates#Next_step... .

All the steps were successful and I manage to combine the requested files into one. I place it under Splunk_home\etc\auth\mycerts\ and restart splunk.

Splunkweb is starting fine but splunkd is not. Can you advise me what I did wrong and how I can get this working? I am new to Splunk as I got the server from another colleague that resigned.

Tags (2)

NOUMSSI
Builder

Hi,

Make sure that there is no application installed on your system that use the port 8089.
Restart splunkd with cmt if you are on windows or with terminal if you are on linux

0 Karma

apentaros
Engager

My server is on Windows 2012 64-bit. I did one netstat -a to list all ports that are used. strangely I don't see the port 8089 to be used not by Splunk nor by other device!

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...