<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to fix 500 internal server error on Splunk  5.0.1 in Security</title>
    <link>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43321#M13815</link>
    <description>&lt;P&gt;I'm experiencing the issue whenever I try to modify saved searches and tried the now available update to 5.0.2. And I'm sorry to report: &lt;STRONG&gt;The problem is not fixed with 5.0.2!&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Feb 2013 16:41:26 GMT</pubDate>
    <dc:creator>dabbank</dc:creator>
    <dc:date>2013-02-26T16:41:26Z</dc:date>
    <item>
      <title>How to fix 500 internal server error on Splunk  5.0.1</title>
      <link>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43316#M13810</link>
      <description>&lt;P&gt;When I do &lt;CODE&gt;Home-&amp;gt;Add Data-&amp;gt;From Files and Directories-&amp;gt;Skip Preview&lt;/CODE&gt; or &lt;CODE&gt;Home-&amp;gt;Add Data-&amp;gt;From Files and Directories-&amp;gt;Preview Data Before Indexing&lt;/CODE&gt; I get a &lt;CODE&gt;'500 internal server error'&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;If I choose '&lt;CODE&gt;Preview Data Before Indexing&lt;/CODE&gt;' it happens after I've chosen the sourcetype and previewed the data, if I choose '&lt;CODE&gt;Skip Preview&lt;/CODE&gt;' it happens right away.&lt;/P&gt;

&lt;P&gt;This is the line in the logs:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;admin:1120 - uiHelper processValueAdd operator failed for endpoint_path=data/inputs/monitor/_new elementName=spl-ctrl_sourcetypeSelect: list index out of range
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The problem first appeared in 5.0, I upgraded to 5.0.1 and I'm still seeing it.  This is a Windows XP machine.  &lt;/P&gt;

&lt;P&gt;I found two hits on similar issues:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/66172/consistent-error-500s-on-file-and-directory-new-definitions"&gt;http://splunk-base.splunk.com/answers/66172/consistent-error-500s-on-file-and-directory-new-definitions&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/7854/splunk-failed-to-fetch-form-values-for-form-savedsearches"&gt;http://splunk-base.splunk.com/answers/7854/splunk-failed-to-fetch-form-values-for-form-savedsearches&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The first hit isn't clear about what was done to fix the problem and the solution in the second hit was just to reinstall.  I'm hoping to avoid that.&lt;/P&gt;

&lt;P&gt;Does anyone have any additional information?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2012 17:05:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43316#M13810</guid>
      <dc:creator>megancarney</dc:creator>
      <dc:date>2012-11-22T17:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix 500 internal server error on Splunk  5.0.1</title>
      <link>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43317#M13811</link>
      <description>&lt;P&gt;@megancarney, changed the "&lt;CODE&gt;5.1&lt;/CODE&gt;" to "&lt;CODE&gt;5.0.1&lt;/CODE&gt;", as I assume this is what you meant.&lt;/P&gt;

&lt;P&gt;If it's not what you meant I apologise as you must be time-travelling as Splunk v5.1 is not a current release. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2012 17:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43317#M13811</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-11-22T17:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix 500 internal server error on Splunk  5.0.1</title>
      <link>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43318#M13812</link>
      <description>&lt;P&gt;The "list index out of range" appears to be a red herring, as I also see it on fresh 5.0.1 install with no observable errors in the UI.  I've filed it as SPL-58736, referencing this question.&lt;/P&gt;

&lt;P&gt;@megancarney: Please open a support case ( &lt;A href="https://www.splunk.com/page/submit_issue"&gt;https://www.splunk.com/page/submit_issue&lt;/A&gt; ) and upload the diagnostic file generated by "splunk diag".  A screenshot of the error in the web browser would also help.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2012 00:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43318#M13812</guid>
      <dc:creator>amrit</dc:creator>
      <dc:date>2012-11-23T00:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix 500 internal server error on Splunk  5.0.1</title>
      <link>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43319#M13813</link>
      <description>&lt;P&gt;This problem is caused by a regression in Splunk 5.0 and 5.0.1 which impacts certain methods to list indexes, such as:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Eventcount" target="_blank"&gt;eventcount&lt;/A&gt; command&lt;/LI&gt;
&lt;LI&gt;REST API calls to the &lt;CODE&gt;/services/data/indexes&lt;/CODE&gt; endpoint&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In 5.0 and 5.0.1, these methods fail to use cached assets and end up iterating over the files of your indexes themselves. This results in a much slower execution, which eventually affects whatever consumer calls the method.&lt;/P&gt;

&lt;P&gt;In the Manager user interface, this affects some of the pages that need to present a list of indexes such as:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The page showing the details of a saved search (Manager &amp;gt; Searches &amp;amp; Reports &amp;gt; $SAVED_SEARCH_NAME)&lt;/LI&gt;
&lt;LI&gt;The setup page for most data inputs (Manager &amp;gt; Data Inputs &amp;gt; Files &amp;amp; Directories &amp;gt; Add new)&lt;/LI&gt;
&lt;LI&gt;The page where you can edit roles (Manager &amp;gt; Access controls &amp;gt; Roles)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If the index-listing method takes more than 30s to complete, Splunkweb will time out on it and display a "500 - internal server error" message.&lt;/P&gt;

&lt;P&gt;This issue will be fixed in maintenance release 5.0.2, which we are aiming to deliver early in 2013. We are also working on intermediary patch release 5.0.1.1 to specifically address this issue.&lt;/P&gt;

&lt;P&gt;For reference, the bugs behind this problem are SPL-57518 and SPL-58650.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;IMPORTANT NOTE:&lt;/STRONG&gt; We are aware of a residual issue in version 5.0.2 that is responsible for timeouts on a smaller set of Manager pages:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Manager » Indexes&lt;/LI&gt;
&lt;LI&gt;Manager » Data inputs » * » Add new&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;This issue will primarily affect systems with many (typically, thousands) of buckets in the hot/warm index directories and running on Windows (which does not passively use available system memory for filesystem cache).&lt;/P&gt;

&lt;P&gt;The bug reference for this issue is SPL-61718 and it is slated to be fixed in 5.0.3. We are also working on the release of a 5.0.2.x patch to address this issue, which you'll be able to obtain by contacting support.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43319#M13813</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2020-09-28T12:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix 500 internal server error on Splunk  5.0.1</title>
      <link>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43320#M13814</link>
      <description>&lt;P&gt;...and this item is listed in the &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.1/ReleaseNotes/Knownissues"&gt;Known Issues&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2012 05:50:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43320#M13814</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2012-12-11T05:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix 500 internal server error on Splunk  5.0.1</title>
      <link>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43321#M13815</link>
      <description>&lt;P&gt;I'm experiencing the issue whenever I try to modify saved searches and tried the now available update to 5.0.2. And I'm sorry to report: &lt;STRONG&gt;The problem is not fixed with 5.0.2!&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2013 16:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43321#M13815</guid>
      <dc:creator>dabbank</dc:creator>
      <dc:date>2013-02-26T16:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix 500 internal server error on Splunk  5.0.1</title>
      <link>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43322#M13816</link>
      <description>&lt;P&gt;There is, unfortunately, a remaining issue in version 5.0.2 that affects certain Manager pages. I have amended my answer to indicate that.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2013 16:52:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43322#M13816</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2013-02-26T16:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix 500 internal server error on Splunk  5.0.1</title>
      <link>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43323#M13817</link>
      <description>&lt;P&gt;I only updated one of our search heads to 5.0.2 and expected the issue to be fixed since you maintain saved searches there. But here I was wrong. You have to update the indexers to benefit from the fix. This is quite strange because you edit saved searches stored on the search head; but that's just how it is.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2013 09:56:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43323#M13817</guid>
      <dc:creator>dabbank</dc:creator>
      <dc:date>2013-02-27T09:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix 500 internal server error on Splunk  5.0.1</title>
      <link>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43324#M13818</link>
      <description>&lt;P&gt;This is due to the nature of this issue, which has to do with gathering the list of indexes present on &lt;STRONG&gt;indexers&lt;/STRONG&gt; from the search-head. The indexers need to have the fix as well so that when they run the 'eventcount' command to list indexes, that doesn't take too long and cause a time out upstream.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2013 15:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-fix-500-internal-server-error-on-Splunk-5-0-1/m-p/43324#M13818</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2013-02-27T15:10:20Z</dc:date>
    </item>
  </channel>
</rss>

