Alerting

Unable to save objects in splunk due to "server abort"

yoshilog
Explorer

We have an issue wherein every time we attempt to create a search macro, create a lookup definition, create a new lookup, update a lookup file name, clone the mentioned knowledge objects,  Splunk responds with " Your entry was not saved. The following error was reported: server abort. splunk " Can you let us know the cause of the issue in our Splunk instance? We are currently unable to create any new search macros in this environment.

 

Capture 1.PNG

They advised that there is a workaround of updating the .conf files in the backend, however our clients don't have access to the backend, and everytime they want to update something, the request goes directly to us. Does anyone know how to resolve this issue? We need the UI to function properly as it is causing delay in delivery.

Labels (1)
0 Karma
1 Solution

yoshilog
Explorer

This issue has now been resolved. It was caused by a Tech Arch Issue wherein the server files for our server were not updated. Clients were not able to update the lookup files due to the presence of a Content Security Policy specific to our server. The unique Content Security Policy (CSP) was only applicable in our region, and the source is currently unknown.
In case you are still experiencing this issue, please reach out to your technology architect (L3 team) who handles your server and have it checked. Thank you.

View solution in original post

0 Karma

yoshilog
Explorer

This issue has now been resolved. It was caused by a Tech Arch Issue wherein the server files for our server were not updated. Clients were not able to update the lookup files due to the presence of a Content Security Policy specific to our server. The unique Content Security Policy (CSP) was only applicable in our region, and the source is currently unknown.
In case you are still experiencing this issue, please reach out to your technology architect (L3 team) who handles your server and have it checked. Thank you.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...