Splunkd is down
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
Splunkd is down
Sometimes Splunk Web may show the message ""Splunkd appears to be down," when splunkd is definitely up and running. There are several potential causes.
Splunkd may need a few more seconds to come up
Sometimes the web server is ready to respond before the daemon. This is usually the case if you have enabled Splunk to work with LDAP, as it can take time for the LDAP authentication to pass. If you notice a lag after reboots, try putting a sleep delay or otherwise making the splunkweb (twistd.py) process wait before it launches.
Some email clients may insert hidden characters (line-breaks, null characters, etc.) in the license string when it gets emailed to you. These hidden characters can break your license string causing Splunk to go down. To resolve this issue you should copy the license string from the store and paste it into your license file in $SPLUNK_HOME/etc/splunk.license or into the License section of Splunk Web.
This documentation applies to the following versions of Splunk: 3.3 , 3.3.1 , 3.3.2 , 3.3.3 , 3.3.4 , 3.4 , 3.4.1 , 3.4.2 , 3.4.3 , 3.4.5 , 3.4.6 , 3.4.8 , 3.4.9 , 3.4.10 , 3.4.11 , 3.4.12 , 3.4.13 , 3.4.14 View the Article History for its revisions.