Deployment Architecture

Issue accessing Splunk Search Head through AWS Load Balancer

swatghare
Path Finder

Hello

I am facing a weird issue while accessing my Splunk Search Head via AWS Load Balancer. We have Splunk Search head cluster deployed on AWS Linux VM and we have placed Application Load Balancer so as to access the most available Splunk Search Head. When we enter the DNS of Load Balancer , we get the splunk search head login page but when we access the search head it do not show all of the features. It only shows, neither it displays the user name who logged in. I am not sure of the issue here but attaching the screenshot of home screen of search head to get idea what I see when I login as Admin.

Does anyone faced this issue earlier , if yes then how can we resolve this?

Regards,
Sushantalt text

Tags (1)
0 Karma
1 Solution

DavidHourani
Super Champion

Hi @swatghare,

This is happening because your LB session is not sticky/persistent so you are losing your pages content. Could you double check and set it to sticky see if it works ?

Official documentation here:
https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/UseSHCwithloadbalancers

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @swatghare,

This is happening because your LB session is not sticky/persistent so you are losing your pages content. Could you double check and set it to sticky see if it works ?

Official documentation here:
https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/UseSHCwithloadbalancers

Cheers,
David

swatghare
Path Finder

Thanks,
Yes this worked , below is the link for enabling sticky session in AWS

https://docs.aws.amazon.com/elasticloadbalancing/latest/application/load-balancer-target-groups.html...

DavidHourani
Super Champion

awesome, thanks for the link !

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...