Deployment Architecture

Why am I no longer able to access Splunkbase from a Search Head after upgrading to Splunk 6.3?

balbano
Contributor

Hi guys,

Not sure if anyone else is having this issue but it seems that ever since I upgrade to Splunk 6.3.x I can no longer access Splunkbase from the Search Head Instance like I used to.

I configured this to work through the proxy.

Can someone confirm with me that this should still work, and if so, which configurations I need to check?

Any help would be much appreciated.

Thanks.
Brian

0 Karma

ssmoot_splunk
Splunk Employee
Splunk Employee

This has been identified as a bug and is resolved in patch 6.3.4.

SPL-112383 "search more apps" feature not working when using proxy

To detect if you are hitting this bug, you can verify in splunkd_ui_access.log that you are generating an HTTP error 502 when trying to reach:
http(s)://...../...../manager/search/appsremote?offset=0&count=20&order=latest

jkat54
SplunkTrust
SplunkTrust

Restart your proxy... fix your proxy... can you curl splunkbase addresses from the server? If not, fix your proxy 😉

0 Karma

balbano
Contributor

Not the proxy... traffic from the search head is not even hitting the proxy to go out. This leads me to believe something may have changed in configuring Splunk to use the proxy to go out to splunkbase. I remember configuring it via Splunk application configuration and not global env variables. (i.e. http_proxy / https_proxy)

However, I did confirm that the proxy servers can reach splunkbase.

-Brian

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!