Deployment Architecture

Issue accessing Splunk Search Head through AWS Load Balancer

swatghare
Path Finder

Hello

I am facing a weird issue while accessing my Splunk Search Head via AWS Load Balancer. We have Splunk Search head cluster deployed on AWS Linux VM and we have placed Application Load Balancer so as to access the most available Splunk Search Head. When we enter the DNS of Load Balancer , we get the splunk search head login page but when we access the search head it do not show all of the features. It only shows, neither it displays the user name who logged in. I am not sure of the issue here but attaching the screenshot of home screen of search head to get idea what I see when I login as Admin.

Does anyone faced this issue earlier , if yes then how can we resolve this?

Regards,
Sushantalt text

Tags (1)
0 Karma
1 Solution

DavidHourani
Super Champion

Hi @swatghare,

This is happening because your LB session is not sticky/persistent so you are losing your pages content. Could you double check and set it to sticky see if it works ?

Official documentation here:
https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/UseSHCwithloadbalancers

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @swatghare,

This is happening because your LB session is not sticky/persistent so you are losing your pages content. Could you double check and set it to sticky see if it works ?

Official documentation here:
https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/UseSHCwithloadbalancers

Cheers,
David

swatghare
Path Finder

Thanks,
Yes this worked , below is the link for enabling sticky session in AWS

https://docs.aws.amazon.com/elasticloadbalancing/latest/application/load-balancer-target-groups.html...

DavidHourani
Super Champion

awesome, thanks for the link !

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...