Alerting

Unable to save objects in splunk due to "server abort"

yoshilog
Explorer

We have an issue wherein every time we attempt to create a search macro, create a lookup definition, create a new lookup, update a lookup file name, clone the mentioned knowledge objects,  Splunk responds with " Your entry was not saved. The following error was reported: server abort. splunk " Can you let us know the cause of the issue in our Splunk instance? We are currently unable to create any new search macros in this environment.

 

Capture 1.PNG

They advised that there is a workaround of updating the .conf files in the backend, however our clients don't have access to the backend, and everytime they want to update something, the request goes directly to us. Does anyone know how to resolve this issue? We need the UI to function properly as it is causing delay in delivery.

Labels (1)
0 Karma
1 Solution

yoshilog
Explorer

This issue has now been resolved. It was caused by a Tech Arch Issue wherein the server files for our server were not updated. Clients were not able to update the lookup files due to the presence of a Content Security Policy specific to our server. The unique Content Security Policy (CSP) was only applicable in our region, and the source is currently unknown.
In case you are still experiencing this issue, please reach out to your technology architect (L3 team) who handles your server and have it checked. Thank you.

View solution in original post

0 Karma

yoshilog
Explorer

This issue has now been resolved. It was caused by a Tech Arch Issue wherein the server files for our server were not updated. Clients were not able to update the lookup files due to the presence of a Content Security Policy specific to our server. The unique Content Security Policy (CSP) was only applicable in our region, and the source is currently unknown.
In case you are still experiencing this issue, please reach out to your technology architect (L3 team) who handles your server and have it checked. Thank you.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...