Admin Manual

 


How Splunk Works

Splunkd is down

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Splunkd is down

Sometimes Splunk Web may show the message ""Splunkd appears to be down," when splunkd is definitely up and running. There are several potential causes.


Splunkd may need a few more seconds to come up

Sometimes the web server is ready to respond before the daemon. This is usually the case if you have enabled Splunk to work with LDAP, as it can take time for the LDAP authentication to pass. If you notice a lag after reboots, try putting a sleep delay or otherwise making the splunkweb (twistd.py) process wait before it launches.


Your license file contains line-breaks or other hidden characters

Some email clients may insert hidden characters (line-breaks, null characters, etc.) in the license string when it gets emailed to you. These hidden characters can break your license string causing Splunk to go down. To resolve this issue you should copy the license string from the store and paste it into your license file in $SPLUNK_HOME/etc/splunk.license or into the License section of Splunk Web.

This documentation applies to the following versions of Splunk: 3.2 , 3.2.1 , 3.2.2 , 3.2.3 , 3.2.4 , 3.2.5 , 3.2.6 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!