Deployment Architecture

Web_service.log is empty after upgrading from Splunk version 7.3 to 8.0.

dolj
Explorer

I have just upgraded my Splunk deployment server from 7.3 to 8.0 and after upgrading the web UI will not come up. I was trying to troubleshoot and was looking at the web_service.log but for some reason it is empty (0 bytes). I cannot figure out why it is not getting any logs or why the UI drops after the upgrade. Any suggestions would be greatly appreciated.

Labels (1)
0 Karma

shivanshu1593
Builder

Error messages in Splunkd can help. Also, please check if the certificate that you've specified in web.conf is still valid or not, and the correct path to the certificate is mentioned over there.

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma

dolj
Explorer

the only thing in ./local/web.conf is

[settings]
startwebserver = 1
~

this is a test DS that I am trying to upgrade before hitting prod.

0 Karma

PavelP
Motivator

Hello @dolj

check splunkd.log for any WARNs or ERRORs directly after the restart

0 Karma

dolj
Explorer

checked the splunkd.log while restarting and there were no WARN or ERROR messages only INFO. When you tail the splunkd.log there are not entries written while starting, stopping, or restarting.

0 Karma

PavelP
Motivator

@dolj
no log entries at all during restart - that's unusual. Does splunk process running?

ps aux | grep -i splunk
0 Karma

dolj
Explorer

not sure why but it wasn't working and it now is.

I found this log related to the web UI

05-24-2020 23:12:06.172 -0400 ERROR UiHttpListener - An applicaiton server has exited unexpectedly, web UI cannot be used until it is restarted

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...