Getting Data In

500 error after splunk reboot

Bulluk
Path Finder

I added a mailhost to splunk and then rebooted as per the notice at the top of the page. When it came back up I got the usual login screen but after login in as the admin account I was greeted with the following error:

InternalServerError: [HTTP 500] Splunkd internal error; [{'text': "In handler 'user-prefs': Application does not exist: user-prefs", 'code': None, 'type': 'ERROR'}]

I've compared the /etc/users directory to a working instance of splunk and can't see any differences. I've checked that the /etc/apps/user-prefs application exists and again it's identical to a working server.

At this point, as a Splunk newb I don't really know what else to look for so any help is really appreciated!

I'm running Splunk 4.2.4 on a Windows 2008 machine

Thanks

Tags (2)
0 Karma
1 Solution

Bulluk
Path Finder

My problem turned out to be a daft one. For reasons that I won't bore you with I have splunk universal forwarder AND the full version of splunk on the same server. As a result, when I performed a restart of splunkweb there was a chance that it would bind to the forwarder port rather than the full instance. The fix was to simply move one of them to another port, ie I now have the forwarder on 8090 and the full instance is on 8091

View solution in original post

0 Karma

Bulluk
Path Finder

My problem turned out to be a daft one. For reasons that I won't bore you with I have splunk universal forwarder AND the full version of splunk on the same server. As a result, when I performed a restart of splunkweb there was a chance that it would bind to the forwarder port rather than the full instance. The fix was to simply move one of them to another port, ie I now have the forwarder on 8090 and the full instance is on 8091

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...