<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunkweb - slow startup in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45035#M1480</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;splunkweb takes ages to start. it even runs into an internal timeout and only with some tweaking (touch /appl/splunk/var/run/splunk/splunkweb.pid) it finally starts up after 2-10 minutes. We experience the same on 6 different Splunk instances. Find below an example which represents the second restart of a splunk instance. This one is faster as the first one but it still takes too long.&lt;/P&gt;

&lt;P&gt;Without tweaking (service log):&lt;BR /&gt;
Starting splunk server daemon (splunkd)...&lt;BR /&gt;
Done.&lt;BR /&gt;
Starting splunkweb...&lt;BR /&gt;
Timed out waiting for splunkweb to start&lt;/P&gt;

&lt;P&gt;With tweaking (web_service.log) :&lt;BR /&gt;
2012-01-05 14:08:26,875 INFO    [4f05a0c7da160f4d0] root:243 - Enabling SSL&lt;BR /&gt;
2012-01-05 14:10:57,546 INFO    [4f05a0c7da160f4d0] root:133 - ENGINE: Serving on 0.0.0.0:443&lt;BR /&gt;
2012-01-05 14:10:57,546 INFO    [4f05a0c7da160f4d0] root:133 - ENGINE: Bus STARTED&lt;/P&gt;

&lt;P&gt;Any idea what migth cause this behaviour?&lt;/P&gt;

&lt;P&gt;OS: Solaris 10&lt;BR /&gt;
HW: x86&lt;BR /&gt;
Splunk: 4.2.5&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jan 2012 13:39:53 GMT</pubDate>
    <dc:creator>kochera</dc:creator>
    <dc:date>2012-01-05T13:39:53Z</dc:date>
    <item>
      <title>Splunkweb - slow startup</title>
      <link>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45035#M1480</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;splunkweb takes ages to start. it even runs into an internal timeout and only with some tweaking (touch /appl/splunk/var/run/splunk/splunkweb.pid) it finally starts up after 2-10 minutes. We experience the same on 6 different Splunk instances. Find below an example which represents the second restart of a splunk instance. This one is faster as the first one but it still takes too long.&lt;/P&gt;

&lt;P&gt;Without tweaking (service log):&lt;BR /&gt;
Starting splunk server daemon (splunkd)...&lt;BR /&gt;
Done.&lt;BR /&gt;
Starting splunkweb...&lt;BR /&gt;
Timed out waiting for splunkweb to start&lt;/P&gt;

&lt;P&gt;With tweaking (web_service.log) :&lt;BR /&gt;
2012-01-05 14:08:26,875 INFO    [4f05a0c7da160f4d0] root:243 - Enabling SSL&lt;BR /&gt;
2012-01-05 14:10:57,546 INFO    [4f05a0c7da160f4d0] root:133 - ENGINE: Serving on 0.0.0.0:443&lt;BR /&gt;
2012-01-05 14:10:57,546 INFO    [4f05a0c7da160f4d0] root:133 - ENGINE: Bus STARTED&lt;/P&gt;

&lt;P&gt;Any idea what migth cause this behaviour?&lt;/P&gt;

&lt;P&gt;OS: Solaris 10&lt;BR /&gt;
HW: x86&lt;BR /&gt;
Splunk: 4.2.5&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2012 13:39:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45035#M1480</guid>
      <dc:creator>kochera</dc:creator>
      <dc:date>2012-01-05T13:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkweb - slow startup</title>
      <link>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45036#M1481</link>
      <description>&lt;P&gt;I spotted slow startup once after I was cleaning up my buckets (splunk clean all). After that Splunk was checking/re-config all buckets (and I have/had a load of buckets) which took some 40mins for startup! But this happened only once after the cleanup!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2012 14:45:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45036#M1481</guid>
      <dc:creator>LCM</dc:creator>
      <dc:date>2012-01-05T14:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkweb - slow startup</title>
      <link>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45037#M1482</link>
      <description>&lt;P&gt;This could indicate issues with DNS, so I would suggest that you check if the DNS server(s) Splunk server is using (/etc/resolv.conf) work correctly.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2012 15:36:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45037#M1482</guid>
      <dc:creator>bojanz</dc:creator>
      <dc:date>2012-01-05T15:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkweb - slow startup</title>
      <link>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45038#M1483</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;we have the problem with each restart. Time drops after multiple restarts within a short time (e.g. 2 hours).&lt;/P&gt;

&lt;P&gt;cheers,&lt;BR /&gt;
andy&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2012 06:27:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45038#M1483</guid>
      <dc:creator>kochera</dc:creator>
      <dc:date>2012-01-06T06:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkweb - slow startup</title>
      <link>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45039#M1484</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;DNS configuration is correct.&lt;/P&gt;

&lt;P&gt;cheers,&lt;BR /&gt;
Andy&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2012 06:29:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45039#M1484</guid>
      <dc:creator>kochera</dc:creator>
      <dc:date>2012-01-06T06:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkweb - slow startup</title>
      <link>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45040#M1485</link>
      <description>&lt;P&gt;How are you "tweaking"?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2013 13:28:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45040#M1485</guid>
      <dc:creator>joelzyla</dc:creator>
      <dc:date>2013-02-22T13:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkweb - slow startup</title>
      <link>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45041#M1486</link>
      <description>&lt;P&gt;I've seen this every now and then on systems with improper DNS settings.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2013 13:31:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45041#M1486</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-02-22T13:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkweb - slow startup</title>
      <link>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45042#M1487</link>
      <description>&lt;P&gt;I think your Splunk  Web is trying to resolve 'splunk.com' while doing a SPLUNK START OR SPLUNK RESTART. You can try and provide connectivity to Public Internet so that splunk can resolve and connect to splunk.com. I faced this same issue recently and found out by doing a &lt;CODE&gt;tail -f /opt/splunk/var/log/splunk/splunkd.log&lt;/CODE&gt; while giving &lt;CODE&gt;splunk restart&lt;/CODE&gt; command, that in some way, splunk is trying to resolve splunk.com and is failing as the system does not have Connectivity to public Internet.&lt;/P&gt;

&lt;P&gt;Check to see if the connectivity is proper and then give the &lt;CODE&gt;splunk restart&lt;/CODE&gt; command, this solved the problem for me.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 18:23:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunkweb-slow-startup/m-p/45042#M1487</guid>
      <dc:creator>ashutoshab</dc:creator>
      <dc:date>2017-09-22T18:23:18Z</dc:date>
    </item>
  </channel>
</rss>

