<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk web down adter debug/refresh in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-web-down-adter-debug-refresh/m-p/362345#M3158</link>
    <description>&lt;P&gt;Hi guys,&lt;BR /&gt;
I've installed a Splunk enterprise 6.5.2 and some Splunk applications.&lt;BR /&gt;
It's a while that when I try to click on refresh button ( splunkserver:port/debug/refresh ) after a couples of minutes the web interface is not reachable anymore and I've to restart splunk.&lt;BR /&gt;
In splunk.log files there are some errors related to the Splunk applications installed but they seem to be not important. &lt;BR /&gt;
Also I see the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR KVStoreBulletinBoardManager - KV Store changed status to failed. KVStore process terminated.
05-04-2017 08:39:23.487 +0200 ERROR KVStorageProvider - An error occurred during the last operation ('saveBatchData', domain: '2', code: '5'): Failed to connect to target host: 127.0.0.1:8191
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What Can I do?&lt;/P&gt;</description>
    <pubDate>Thu, 04 May 2017 06:45:49 GMT</pubDate>
    <dc:creator>faustf</dc:creator>
    <dc:date>2017-05-04T06:45:49Z</dc:date>
    <item>
      <title>Splunk web down adter debug/refresh</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-web-down-adter-debug-refresh/m-p/362345#M3158</link>
      <description>&lt;P&gt;Hi guys,&lt;BR /&gt;
I've installed a Splunk enterprise 6.5.2 and some Splunk applications.&lt;BR /&gt;
It's a while that when I try to click on refresh button ( splunkserver:port/debug/refresh ) after a couples of minutes the web interface is not reachable anymore and I've to restart splunk.&lt;BR /&gt;
In splunk.log files there are some errors related to the Splunk applications installed but they seem to be not important. &lt;BR /&gt;
Also I see the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR KVStoreBulletinBoardManager - KV Store changed status to failed. KVStore process terminated.
05-04-2017 08:39:23.487 +0200 ERROR KVStorageProvider - An error occurred during the last operation ('saveBatchData', domain: '2', code: '5'): Failed to connect to target host: 127.0.0.1:8191
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What Can I do?&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 06:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-web-down-adter-debug-refresh/m-p/362345#M3158</guid>
      <dc:creator>faustf</dc:creator>
      <dc:date>2017-05-04T06:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk web down adter debug/refresh</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-web-down-adter-debug-refresh/m-p/362346#M3159</link>
      <description>&lt;P&gt;Sounds like there is something going wrong with the KV store (mongo) during this operation. &lt;/P&gt;

&lt;P&gt;First place I would look is in mongod.log. ($splunk_home/var/log/splunk/mongod.log)&lt;/P&gt;

&lt;P&gt;Second thing I would do is make sure your KVstore is loading ok normally. I would start by checking stuff like certs which KV store uses to self-validate:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/404979/trying-to-run-the-distributed-management-console-g.html"&gt;https://answers.splunk.com/answers/404979/trying-to-run-the-distributed-management-console-g.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Third thing I would do is confirm you actually use KVstore here, and that this message is not a red herring.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 07:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-web-down-adter-debug-refresh/m-p/362346#M3159</guid>
      <dc:creator>bohanlon_splunk</dc:creator>
      <dc:date>2017-05-09T07:14:01Z</dc:date>
    </item>
  </channel>
</rss>

