Author: Frank Wayne

  • Splunk 10.2.5 Doesn’t Always “stop”

    Recently, an upgrade on a couple of Splunk 10.2.5 servers on Red Hat 8.10 failed with unexpected messages. During the first startup of 10.2.7, the migration to the new version stopped with

    ERROR: In order to migrate, Splunkd must not be running.

    Splunk had presumably been stopped well before this. When ckecking splunk status, the license agreement and migration prompts would be presented — even though --accept-license --answer-yes were provided — and the process stopped again with the above error message.

    I used an explicit splunk stop before starting the upgrade, then ran ps -e | grep splunk after the process reported that Splunk and helper processes had been stopped, and I still found Splunk processes.

    # /opt/splunk/bin/splunk stop
    Stopping splunkd...
    Shutting down. Please wait, as this may take a few minutes.
    ................... [ OK ]
    Stopping splunk helpers...
    [ OK ]
    Done.
    # ps -e | grep splunk
    4185174 ? 00:00:08 splunkd
    4185175 ? 00:00:00 splunkd
    4185306 ? 00:00:00 splunkd
    4185307 ? 00:00:00 splunkd
    4185327 ? 00:00:07 splunkd
    4185328 ? 00:00:00 splunkd
    4185331 ? 00:00:07 splunkd
    4185332 ? 00:00:00 splunkd
    4185336 ? 00:00:08 splunkd
    4185337 ? 00:00:00 splunkd

    killall splunkd fixed the problem in the above case, but on another server not only were there instances of splunkd running but other splunk processes like splunk-supervis also. I had to kill these individually to continue with the upgrade.

    I could not find any reason in the logs for these processes to have been abandoned or ignored, nor do I see any known issues. A similar problem was reported by a user upgrading a Universal Forwarder to version 8.2.4 back in 2022. The article points out that the installer script checks for the Splunk binary in the file system and runs splunk stop if it exists. There is no check for an error result (though in my case stop does not return an error), nor does it check if all processes were terminated.

    I added steps to check for running Splunk processes in my upgrade scripts.

  • Technitium DNS Splunk Add-on Updated to v0.1.1

    I have revised my Technitium DNS Add-on to fix a problem with ingestion of JSON logs. I also updated and added some refreshes to the dashboard.

    I noticed some unusual reporting on the dashboard yesterday and discovered that the dns.json file was sometimes being ignored. Splunk was reporting an error monitoring the file:

    ERROR TailReader [1423568 tailreader0] - File will not be read, seekptr checksum did not match (file=/var/log/technitium/dns/dns.json). Last time we saw this initcrc, filename was different. You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source. Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.

    I increased the initCrcLength to 2048 and the problem was solved. Installing this update will cause all of the log files to be re-ingested, so if you have v0.1.0 installed, you will want to move any ingested log files somewhere else before pushing this update to your forwarder.

    The dashboard was updated to do refreshes at 2-minute intervals. Not all the panels were refreshing, so I added refreshes where necessary.

    The add-on has been updated on Splunkbase.

  • Technitium DNS Add-on Approved on Splunkbase

    My Technitium Add-on was approved and is now available on Splunkbase.

    I invite comments on the features and functionality in your environments, so please try it and let me know what you like, what doesn’t work and what features you would like to see.

  • WayneWare Blog Launched

    Welcome to the WayneWare blog!

    WayneWare is my home for software projects, with an initial focus on Splunk add-ons and related tools. Over time, you’ll also find other utilities, libraries, and applications that I build and maintain under the WayneWare name.

    This blog will serve as a place to share product announcements, release notes, technical articles, development insights, and the occasional behind-the-scenes look at how these projects come together.

    Over the coming weeks, I’ll be rebranding my existing applications under the WayneWare banner. As that work progresses, I’ll be publishing updates here along with news about new releases.

    Thanks for stopping by, and check back soon—there’s much more to come.

  • Technitium DNS Add-on Released

    I have released the WayneWare Add-on for Technitium DNS today. This initial version performs field extraction for all query records and assigns source types for the various categories of events that the server produces.

    The add-on is only available for *nix and is written for a normal (non-container) installation of the server.

    There is a dashboard included. I invite comments as to what additional features the dashboard can include.