Alerting

Unable to save objects in splunk due to "server abort"

yoshilog
Explorer

We have an issue wherein every time we attempt to create a search macro, create a lookup definition, create a new lookup, update a lookup file name, clone the mentioned knowledge objects,  Splunk responds with " Your entry was not saved. The following error was reported: server abort. splunk " Can you let us know the cause of the issue in our Splunk instance? We are currently unable to create any new search macros in this environment.

 

Capture 1.PNG

They advised that there is a workaround of updating the .conf files in the backend, however our clients don't have access to the backend, and everytime they want to update something, the request goes directly to us. Does anyone know how to resolve this issue? We need the UI to function properly as it is causing delay in delivery.

Labels (1)
0 Karma
1 Solution

yoshilog
Explorer

This issue has now been resolved. It was caused by a Tech Arch Issue wherein the server files for our server were not updated. Clients were not able to update the lookup files due to the presence of a Content Security Policy specific to our server. The unique Content Security Policy (CSP) was only applicable in our region, and the source is currently unknown.
In case you are still experiencing this issue, please reach out to your technology architect (L3 team) who handles your server and have it checked. Thank you.

View solution in original post

0 Karma

yoshilog
Explorer

This issue has now been resolved. It was caused by a Tech Arch Issue wherein the server files for our server were not updated. Clients were not able to update the lookup files due to the presence of a Content Security Policy specific to our server. The unique Content Security Policy (CSP) was only applicable in our region, and the source is currently unknown.
In case you are still experiencing this issue, please reach out to your technology architect (L3 team) who handles your server and have it checked. Thank you.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...