<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is happening in Splunk Enterprise V9.1.0.1 ? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/669313#M17898</link>
    <description>&lt;P&gt;Last week v9.1.2 has been released. (6 nov 2023, I think it was)&lt;BR /&gt;&lt;BR /&gt;After installing this version on my test instance (v9.1.1) everytyhing seems to work again including sendemail - no issues found. Great!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;After installing this version several days later on our production instance (9.1.0.2) also sendemail was working fine again. Great!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;NB. after that I was also able to fix all other issues on our production instance as mentioned before in this post, like: kvstore, secure gateway etc Great!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Many thanks to support- and development team. I am now happy splunking again!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I hereby close this post.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2023 11:54:43 GMT</pubDate>
    <dc:creator>apietersen</dc:creator>
    <dc:date>2023-11-21T11:54:43Z</dc:date>
    <item>
      <title>What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651297#M16864</link>
      <description>&lt;P&gt;&lt;STRONG&gt;RE: Case #3270697 After upgrade to 9.1.01 not able to send emails eg. of critical alerts! [ ref:_00D409oyL._5005a2bGRKI:ref ]&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;After upgrade to v9.1.0.1 Splunk Enterprise, (single instance), last weekend (15 Juli 2023) + changing admin password as was suggested by Assist (which throws an error now !?)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;1) Message when using sendemail:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_0-1689859493539.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26371iAA587BF51DCA9C6C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_0-1689859493539.png" alt="apietersen_0-1689859493539.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Smpt setting: O365&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_1-1689855102470.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26367iE29B2F924F2FCB77/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_1-1689855102470.png" alt="apietersen_1-1689855102470.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Checked the login on O365, ofcourse&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2) Assist stopped running???&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_2-1689855102473.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26366i1673EF6D4599550B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_2-1689855102473.png" alt="apietersen_2-1689855102473.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3) Also:&lt;BR /&gt;&lt;BR /&gt;3a&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_3-1689855102483.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26370i5C96D7CEA51292C0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_3-1689855102483.png" alt="apietersen_3-1689855102483.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;3b&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_0-1689863439907.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26375iC0998FCBBD81893B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_0-1689863439907.png" alt="apietersen_0-1689863439907.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;4) new GUI / layout ?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_4-1689855102484.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26368i4F5734ECCF19296F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_4-1689855102484.png" alt="apietersen_4-1689855102484.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5) Annoying and not working “Don’t show this again” message on every page. Just stepping to another dashboard on the same server/domain ??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_5-1689855102489.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26369iCBEDDF7A0FE79ED3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_5-1689855102489.png" alt="apietersen_5-1689855102489.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;6) endless waiting:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_0-1689860492567.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26372i093B515880CE1D6A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_0-1689860492567.png" alt="apietersen_0-1689860492567.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is next?&lt;BR /&gt;&lt;BR /&gt;Anyone else suffering from the same issues?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 14:30:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651297#M16864</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-20T14:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651462#M16871</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;based on that kvstore/mongodb message I suspect that mongoldb is not running? You could check it's status by&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk show kvstore-status --verbose&lt;/LI-CODE&gt;&lt;P&gt;If it's not up and running you you'd found there reason from $SPLUNK_HOME/var/log/splunk/mongod.log &amp;nbsp;&lt;/P&gt;&lt;P&gt;Probably most common reason for "not running kvstore/mongod" is expired TLS certificate.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 11:22:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651462#M16871</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-07-21T11:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651509#M16874</link>
      <description>&lt;P&gt;Thanks I will check...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 15:14:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651509#M16874</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-21T15:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651575#M16880</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi isoutamo&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;I ran the kwstore diag, as admin:&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_0-1690006566891.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26402i3FE94CB4F29E73BB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_0-1690006566891.png" alt="apietersen_0-1690006566891.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;not sure if this is TLS related?&lt;/LI&gt;&lt;LI&gt;also do not understand why I should have TLS enabled to acces to something running on the same single server/Splunk Enterprise instance?&lt;/LI&gt;&lt;LI&gt;where can I disable this in conf file?&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;or how to renwe cert??&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2023 08:57:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651575#M16880</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-22T08:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651576#M16881</link>
      <description>&lt;P&gt;mongod.log shows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2023-07-21T21:14:54.507+0200 W CONTROL [main] Option: sslMode is deprecated. Please use tlsMode instead.
2023-07-21T21:14:54.508+0200 W CONTROL [main] Option: sslCipherConfig is deprecated. Please use tlsCipherConfig instead.
2023-07-21T21:14:54.508+0200 W CONTROL [main] Option: sslAllowConnectionsWithoutCertificates is deprecated. Please use tlsAllowConnectionsWithoutCertificates instead.
2023-07-21T21:14:54.508+0200 W CONTROL [main] Option: sslAllowInvalidHostnames is deprecated. Please use tlsAllowInvalidHostnames instead.
2023-07-21T21:14:54.508+0200 W CONTROL [main] Option: sslAllowInvalidCertificates is deprecated. Please use tlsAllowInvalidCertificates instead.
2023-07-21T21:14:54.508+0200 W CONTROL [main] Option: sslCertificateSelector is deprecated. Please use tlsCertificateSelector instead.
2023-07-21T19:14:54.513Z W CONTROL [main] net.tls.tlsCipherConfig is deprecated. It will be removed in a future release.
2023-07-21T19:14:54.528Z W NETWORK [main] sslCipherConfig parameter is not supported with Windows SChannel and is ignored.
2023-07-21T19:14:54.529Z W NETWORK [main] sslCipherConfig parameter is not supported with Windows SChannel and is ignored.
2023-07-21T19:14:54.529Z F NETWORK [main] The provided SSL certificate is expired or not yet valid.
2023-07-21T19:14:54.529Z F - [main] Fatal Assertion 50755 at src\mongo\util\net\ssl_manager_windows.cpp 1609
2023-07-21T19:14:54.529Z F - [main] \n\n***aborting after fassert() failure\n\n&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Where and what can I change to get it working again or ignore these TLS SSL and/expired messages?&lt;/LI&gt;&lt;LI&gt;Where to renew these "indoor"&amp;nbsp; TLS certs&amp;nbsp; (self-signed cert I assume and hope) ?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Splunk.log shows:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;07-22-2023 11:05:55.181 +0200 WARN  SearchOperator:kv [13064 SchedulerThread] - Could not find a transform named REPORT-USPS-OFFLINE-CSV
07-22-2023 11:05:55.181 +0200 WARN  SearchOperator:kv [13064 SchedulerThread] - Could not find a transform named REPORT-Camera1
07-22-2023 11:05:55.181 +0200 WARN  SearchOperator:kv [13064 SchedulerThread] - Could not find a transform named REPORT-usps-off4
07-22-2023 11:05:55.181 +0200 WARN  SearchOperator:kv [13064 SchedulerThread] - Could not find a transform named REPORT-USPS-OFFLINE-CSV
07-22-2023 11:05:55.181 +0200 WARN  SearchOperator:kv [13064 SchedulerThread] - Could not find a transform named REPORT-usps-off4
07-22-2023 11:05:55.181 +0200 WARN  SearchOperator:kv [13064 SchedulerThread] - Could not find a transform named REPORT-USPS-OFFLINE-CSV
07-22-2023 11:05:55.181 +0200 WARN  SearchOperator:kv [13064 SchedulerThread] - Could not find a transform named REPORT-Camera1
07-22-2023 11:05:55.213 +0200 INFO  NoahSearchPeerFetcher [13064 SchedulerThread] - Fetch requested. sid=scheduler__nobody__search__RMD5883a9bd5121d9759_at_1690016700_59 use_cache=1
07-22-2023 11:06:00.268 +0200 INFO  ExecProcessor [10852 ExecProcessor] - setting reschedule_ms=59732, for command="D:\Program Files\Splunk\bin\Python3.exe" "D:\Program Files\Splunk\etc\apps\search\bin\quarantine_files.py"&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2023 09:09:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651576#M16881</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-22T09:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651596#M16884</link>
      <description>&lt;P&gt;As it said your tls/ssl cert has expired you need to renew it.&amp;nbsp;&lt;BR /&gt;If you are using Splunk’s default certs (you shouldn’t), just remove/rename old certificate file and restart splunk. That will generate a new one. If you are using official from some cert authority or your own, then you must get a new from there and replace current with that.&lt;/P&gt;&lt;P&gt;You could check that e.g. with command&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;openssl x509 -in mycert.pem -text -noout&lt;/LI-CODE&gt;&lt;P&gt;This told the validity and who has guaranteed it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2023 08:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651596#M16884</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-07-22T08:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651690#M16895</link>
      <description>&lt;P&gt;Our https certificate (web) is not expired. So what and where should I remove this old cert reference.&lt;BR /&gt;We only run Indexer, SH , licens Manager and Kvstore process....and nothing else&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_0-1690183018467.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26412iF41B024680767AF7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_0-1690183018467.png" alt="apietersen_0-1690183018467.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please note: we run a small and single Splunk Enterprise instance on a Intel 16core , 64Gb mem, and 2Tb hardware under windows2019.&lt;BR /&gt;&lt;BR /&gt;BTW How many certs do I need to run and manage in v9.1.0.1?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 07:19:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651690#M16895</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-24T07:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651703#M16896</link>
      <description>&lt;P&gt;Update:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SORRY, AT THE MOMENT NOT MUCH HAPPY SPLUNKING HERE&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;STRONG&gt;WE RUN A 2nd Splunk Enterprise server (FOR TEST/DEV etc) and most issue mentioned below shows on both machines….&lt;BR /&gt;&lt;BR /&gt;Nb. A week before we upgraded our production machine we installed v9.0.1 on our test-server and we only noticed point 5 and 6 but were not alarmed by the things that would come later after we decided to go forward. It came to our attention after we did not see any Alerts and other emails were send.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;After upgrade to v9.1.0.1 Splunk Enterprise, (single instance), last weekend (15 Juli 2023) + changing admin password as was suggested by Assist (which throws an error today / now !?)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;1) Message when using sendemail:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_0-1690184161455.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26413i1731CD9716A7AC27/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_0-1690184161455.png" alt="apietersen_0-1690184161455.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Smpt setting: O365&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_1-1690184161456.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26416i66B66D15CFC7E384/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_1-1690184161456.png" alt="apietersen_1-1690184161456.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checked the login on O365, ofcourse&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ITEM 1 IS STILL NOT SOLVED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2) Assist stopped running???&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_2-1690184161470.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26415i98B63BA6B453ED74/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_2-1690184161470.png" alt="apietersen_2-1690184161470.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ITEM 2 IS STILL NOT SOLVED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3) Also issue with:&lt;BR /&gt;&lt;BR /&gt;3a&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_3-1690184161473.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26418i73D8C04D303DB1CA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_3-1690184161473.png" alt="apietersen_3-1690184161473.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3b -after restart:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_4-1690184161481.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26417iA3730199E1E6B8D4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_4-1690184161481.png" alt="apietersen_4-1690184161481.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;ITEM &amp;nbsp;3a and 3b IS STILL NOT SOLVED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;4) new GUI / layout ?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_5-1690184161483.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26419i051EC343DF21A7B5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_5-1690184161483.png" alt="apietersen_5-1690184161483.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;ITEM &amp;nbsp;4 IS NOT ANSWERED YET&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;5) Annoying and not working “Don’t show this again” message on every page. Just stepping to another dashboard on the same server/domain ??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_6-1690184161485.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26422iB16C16CFA30F7608/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_6-1690184161485.png" alt="apietersen_6-1690184161485.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;ITEM 5 HAS BEEN SOLVED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;6) endless waiting:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_7-1690184161486.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26421i44C78C656C50D9CE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_7-1690184161486.png" alt="apietersen_7-1690184161486.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_8-1690184161487.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26420iAB13A5436F88C75B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_8-1690184161487.png" alt="apietersen_8-1690184161487.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;ITEM &amp;nbsp;6 IS STILL NOT SOLVED – ANY CONFIG CHANGED IN WEB GUI IS NOT WORKING AND ANY CONFIG PAGE KEEPS HANGING. "Loading"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 07:43:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651703#M16896</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-24T07:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651704#M16897</link>
      <description>&lt;P&gt;There are own certificates for web, splunkd and traffic between UFs and indexers. Mongod is using the same certificate as splunkd. You should check from server.conf where it is.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 07:54:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651704#M16897</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-07-24T07:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651713#M16898</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;looked in server.conf: (both test server + production)&lt;BR /&gt;&lt;BR /&gt;Sorry , can not find any path or refence to certificates?&lt;BR /&gt;&lt;BR /&gt;test-server:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_0-1690187635286.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26425iB658572A3AA8CDDF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_0-1690187635286.png" alt="apietersen_0-1690187635286.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 08:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651713#M16898</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-24T08:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651723#M16899</link>
      <description>&lt;P&gt;On my Test-server, I have copied a fresh server.conf from default directory and changed the license manager field. It is coming up and I can login but but still hangs on endless "loading..." when trying to change something (like restart)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_0-1690189485310.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26428i6E9169702D55D6E5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_0-1690189485310.png" alt="apietersen_0-1690189485310.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also Assist show an error:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_1-1690189563030.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26429iFF8682FA4C1AB143/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apietersen_1-1690189563030.png" alt="apietersen_1-1690189563030.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651723#M16899</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-24T14:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651775#M16905</link>
      <description>&lt;P&gt;sorry, both on test-server and on production server shows:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apietersen_0-1690207839243.png" style="width: 613px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26435i3349A51EA9C9D005/image-dimensions/613x103?v=v2" width="613" height="103" role="button" title="apietersen_0-1690207839243.png" alt="apietersen_0-1690207839243.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:21:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651775#M16905</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-24T14:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651782#M16906</link>
      <description>&lt;P&gt;You should use btool to check what and where those configurations are set.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool server list --debug&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:53:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/651782#M16906</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-07-24T14:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652000#M16925</link>
      <description>&lt;P&gt;Update:&lt;BR /&gt;&lt;BR /&gt;Yesterday we had a remote session (Zoom) with Splunk Support. No quick fix found. It needs to be investigated further:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Their observations:&lt;/P&gt;&lt;P&gt;------------------&lt;/P&gt;&lt;P&gt;- After upgrading the Splunk version to 9.1.0.1, the sendemail command is not working it is giving some errors on the production instance and test instance.&lt;/P&gt;&lt;P&gt;command="sendemail", The email domains of the recipients are not among those on the allowed domain list. while sending mail to: &lt;A href="mailto:a.pietersen@eremote.nl" target="_blank"&gt;a.pietersen@....&amp;nbsp;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;command="sendemail", (530, b'5.7.57 Client not authenticated to send mail. [AS4P195CA0039.EURP195.PROD.OUTLOOK.COM 2023-07-25T10:35:23.523Z 08DB887EFF8B2458]', 'pietersen@i....) while sending mail to: &lt;A href="mailto:a.pietersen@eremote.nl" target="_blank"&gt;a.pietersen@....&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- The top of the screen showed a loading icon as I was reviewing the Server settings for the Email settings. Nothing can be done on the Email settings page.&lt;/P&gt;&lt;P&gt;- Additionally, we attempted to restart the UI by accessing the server controls. The loading icon at the top of the page appeared on the server control page as well, indicating the same problem.&lt;/P&gt;&lt;P&gt;- Additionally, the Splunk assist page is not working and displays the error message "Error Loading Splunk Assist."&lt;/P&gt;&lt;P&gt;- Even though we attempted to restart the search head using the CLI, the errors and issues persisted after the restart.&lt;/P&gt;&lt;P&gt;------------------&lt;BR /&gt;&lt;BR /&gt;Thanks, hope they can find a remedy soon, because I am out of my option for now.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 05:43:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652000#M16925</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-26T05:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652029#M16931</link>
      <description>&lt;P&gt;Normally this &amp;nbsp;message means, that your smtp relay don’t allow you to send email with your from-domain. Are you sure that your M365 exchange has configured to relay those emails?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 09:40:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652029#M16931</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-07-26T09:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652030#M16932</link>
      <description>&lt;P&gt;You should replace mycert.pem with your own cert file. That name you could see by previous btool. Use also full path to this file. Sometimes it’s also needed to add “splunk cmd OpenSSL” instead of just “openssl”.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 09:43:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652030#M16932</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-07-26T09:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652033#M16933</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;Both account belongs to me but have different domains. (and no trust-relation in place) Manual sending is no problem and use this daily. It was working for years now based on O365, it sopped after the upgarde. Besides no messages were received form MS that O365 have changed their relay rules. So for now I suspect something not OK in the Splunk 9.1.0.1 environment.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 10:10:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652033#M16933</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-26T10:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652034#M16934</link>
      <description>&lt;P&gt;OK I will try:&amp;nbsp;&lt;SPAN&gt;“splunk cmd OpenSSL” instead of just “openssl”.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 10:13:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652034#M16934</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-26T10:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652036#M16935</link>
      <description>Please use lowercase version for openssl. Autocorrect has meshed it &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;</description>
      <pubDate>Wed, 26 Jul 2023 10:39:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652036#M16935</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-07-26T10:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: What is happening in Splunk Enterprise V9.1.0.1 ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652037#M16936</link>
      <description>&lt;P&gt;Thanks, I will do. &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 10:41:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-p/652037#M16936</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2023-07-26T10:41:36Z</dc:date>
    </item>
  </channel>
</rss>

