Deployment Architecture

Why is there a long delay logging into Splunk on the latest Linux version?

aleivo
Engager

I'm running the latest 7.2.5 Linux version, but even in the last few previous versions, when connecting to Splunk and being presented with the log in screen, after entering a valid username and password and clicking login, it takes pretty much spot on 60 seconds for the login screen to disappear and be presented with the home page.

Even if immediately after successfully logging in through Chrome I start another web browser (IE) and attempt to log in, again it takes consistently 60 seconds for the login to complete. Since this happens with IE and Chrome, perhaps it's not a browser related issue. Also this happens consistently even after a fresh reboot. Other than that the search performance once logged in is pretty quick and the Web UI is quite responsive.

This login issue is fairly annoying and I would like some ideas to troubleshoot the cause of this.

Thanks
Alex

0 Karma
1 Solution

nickhills
Ultra Champion

Is this Splunk local authentication, or LDAP/SAML?

If my comment helps, please give it a thumbs up!

View solution in original post

0 Karma

nickhills
Ultra Champion

Is this Splunk local authentication, or LDAP/SAML?

If my comment helps, please give it a thumbs up!
0 Karma

aleivo
Engager

Aha! You're spot on. The local admin account logs in fast but the slow logins are with LDAP authenticated accounts.

Turns out a while back some AD servers were decommissioned and Splunk was still trying to auth against them and timing out as it was going through its list of configured LDAP servers.

Thanks!
Alex

0 Karma

nickhills
Ultra Champion

I was going to say - 60 seconds sounds like a timeout issue, so that was my hunch!

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...