|
When running trying to run a search via the CLI (Redhat Linux) I get the following message: "Splunk is not running, and it must be for this operation. To start splunk, run "splunk start"." However the Splunk is up and running and fully functional via the Webgui. Any ideas on how to get this working? |
Have there been any recent configuration changes to Splunk? Which account started Splunk? Which account owns the files in $SPLUNK_HOME/var/run/splunk?
Started by root Ownership of $SPLUNK_HOME/var/run/splunk is root