<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk UBA is down in Splunk User Behavior Analytics</title>
    <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565798#M37</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/177803"&gt;@lakshman239&lt;/a&gt;&amp;nbsp; I did run a health check before running stop-all and observed below error:&lt;/P&gt;&lt;P&gt;ui connect: &amp;lt;hostname&amp;gt; &amp;lt;= curl failed to ui &amp;lt;hostname&amp;gt;&lt;BR /&gt;curl: (7) Failed to connect to &amp;lt;hostname&amp;gt; port 443: Connection refused&lt;BR /&gt;ui connect: sc2-splunk-uba-1 &amp;lt;= curl failed to ui &amp;lt;hostname&amp;gt;&lt;BR /&gt;curl: (7) Failed to connect to &amp;lt;hostname&amp;gt; port 443: Connection refused&lt;/P&gt;</description>
    <pubDate>Fri, 03 Sep 2021 13:28:03 GMT</pubDate>
    <dc:creator>snisaxena</dc:creator>
    <dc:date>2021-09-03T13:28:03Z</dc:date>
    <item>
      <title>Splunk UBA is down</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565744#M31</link>
      <description>&lt;P&gt;Splunk UBA search head is down.&lt;/P&gt;&lt;P&gt;Even after restarting ui services, status is shown as active in CLI but GUI is not available.&lt;/P&gt;&lt;P&gt;Commands used to stop/start ui service:&lt;/P&gt;&lt;P&gt;sudo service caspida-ui stop&lt;BR /&gt;&amp;nbsp;sudo service caspida-ui start&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Status when checked in CLI:&lt;/P&gt;&lt;P&gt;● &lt;FONT size="2"&gt;caspida-ui.service&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Loaded: loaded (/etc/init.d/caspida-ui; bad; vendor preset: enabled)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;Active: active (exited)&lt;/STRONG&gt; since Fri 2021-09-03 05:53:12 UTC; 6min ago&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I also tried rebooting the VM, but it doesn't help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I please get a suggestion around how to fix this?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 06:02:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565744#M31</guid>
      <dc:creator>snisaxena</dc:creator>
      <dc:date>2021-09-03T06:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UBA is down</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565783#M32</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238048"&gt;@snisaxena&lt;/a&gt;&amp;nbsp; One option would be stop and start all services, so they start gracefully. Pls refer to -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/UBA/5.0.4.1/Admin/CLICommands" target="_blank"&gt;https://docs.splunk.com/Documentation/UBA/5.0.4.1/Admin/CLICommands&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 12:11:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565783#M32</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2021-09-03T12:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UBA is down</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565793#M34</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/177803"&gt;@lakshman239&lt;/a&gt;I ran /opt/caspida/bin/Caspida stop-all and it has been running since more than 2 hours now.&lt;BR /&gt;I tried to exit and run /opt/caspida/bin/Caspida start-all. It was aborted with below message:&lt;/P&gt;&lt;P&gt;failed to check/update system configuration: aborting. see /var/vcap/sys/log/caspida/caspida.out&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 13:13:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565793#M34</guid>
      <dc:creator>snisaxena</dc:creator>
      <dc:date>2021-09-03T13:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UBA is down</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565796#M36</link>
      <description>&lt;P&gt;stop-all running for long time does indicate an underlying issue in the cluster.&lt;/P&gt;&lt;P&gt;Have you run the pre-check and post health checks using the latest available scripts? If not, please run them and perhaps raise a case with support attaching the output.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 13:24:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565796#M36</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2021-09-03T13:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UBA is down</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565798#M37</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/177803"&gt;@lakshman239&lt;/a&gt;&amp;nbsp; I did run a health check before running stop-all and observed below error:&lt;/P&gt;&lt;P&gt;ui connect: &amp;lt;hostname&amp;gt; &amp;lt;= curl failed to ui &amp;lt;hostname&amp;gt;&lt;BR /&gt;curl: (7) Failed to connect to &amp;lt;hostname&amp;gt; port 443: Connection refused&lt;BR /&gt;ui connect: sc2-splunk-uba-1 &amp;lt;= curl failed to ui &amp;lt;hostname&amp;gt;&lt;BR /&gt;curl: (7) Failed to connect to &amp;lt;hostname&amp;gt; port 443: Connection refused&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 13:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565798#M37</guid>
      <dc:creator>snisaxena</dc:creator>
      <dc:date>2021-09-03T13:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UBA is down</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565799#M38</link>
      <description>&lt;P&gt;did this setup work in the past? If so, has there been any changes to IP/host/dns resolution and/or firewall/connectivity? looks like connectivity/resolution issue&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 13:31:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565799#M38</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2021-09-03T13:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UBA is down</title>
      <link>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565801#M39</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/177803"&gt;@lakshman239&lt;/a&gt;&amp;nbsp; I suspect so too. However, there is no confirmation from network team regarding any connection changes wrt firewall, etc.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 13:42:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-User-Behavior-Analytics/Splunk-UBA-is-down/m-p/565801#M39</guid>
      <dc:creator>snisaxena</dc:creator>
      <dc:date>2021-09-03T13:42:18Z</dc:date>
    </item>
  </channel>
</rss>

