Getting Data In

Splunk Add-On Builder UI is Blank/Won't Load

marycordova
SplunkTrust
SplunkTrust

I've installed the Splunk Add-On Builder but the UI is blank/won't load...I've tried installing on my HF (Heavy Forwarder) and my DS (Deployment Server) (HF is under a lot of load) but still the problem persists.  

@marycordova
0 Karma
1 Solution

marycordova
SplunkTrust
SplunkTrust

I opened a support ticket, and they discovered that my Okta/SAML/SSO had a "role" (for my SH (search head)) that was not present on my DS or HF (it wasn't necessary).  However, my account was inheriting the "admin" role so IMO it shouldn't have mattered.  I added the "role" to my HF and DS and was able to proceed.  

But then...it happened again in another part of the UI.  I opened another support ticket and the advice was not to use Add-On Builder in a distributed environment...which didn't make sense, what would having a distributed environment have to do with it?  

What Add-On Builder does not like, I suspect, is basically any instance of Splunk with "roles" associated to accounts that are not the local/default admin and ONLY the local/default admin.

I deployed a stand-alone, local, Enterprise instance on my laptop NOT integrated with Okta/SAML/SSO and everything works fine...so that is the solution :face_savoring_food:

@marycordova

View solution in original post

0 Karma

marycordova
SplunkTrust
SplunkTrust

I opened a support ticket, and they discovered that my Okta/SAML/SSO had a "role" (for my SH (search head)) that was not present on my DS or HF (it wasn't necessary).  However, my account was inheriting the "admin" role so IMO it shouldn't have mattered.  I added the "role" to my HF and DS and was able to proceed.  

But then...it happened again in another part of the UI.  I opened another support ticket and the advice was not to use Add-On Builder in a distributed environment...which didn't make sense, what would having a distributed environment have to do with it?  

What Add-On Builder does not like, I suspect, is basically any instance of Splunk with "roles" associated to accounts that are not the local/default admin and ONLY the local/default admin.

I deployed a stand-alone, local, Enterprise instance on my laptop NOT integrated with Okta/SAML/SSO and everything works fine...so that is the solution :face_savoring_food:

@marycordova
0 Karma

livehybrid
Ultra Champion

Hi @marycordova 

When you navigate to the UI, try opening DevTools/Console (this depends per browser) and have a look at the console when you load the Add-on builder UI - are there any errors or 4xx/5xx errors in there? This might help point to why it isnt loading correctly.

Let us know if you see any errors and can try and help further.

Regards

Will

0 Karma

Shakira1
Explorer

I have the same issue

I installed it locally on Splunk local host, and the page "home" is empty 

 any idea?

Screenshot 2025-02-19 at 18.16.03.png

0 Karma

marycordova
SplunkTrust
SplunkTrust

Make sure you are using the local/default admin account and that there are no other roles associated with that account. 

@marycordova
0 Karma

Shakira1
Explorer

Yes.

this is my localhost so I use admin local user (the default one) and its have the max permission 

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...