Getting Data In

Splunk dashboard "could not create search" on external network

jadengoho
Builder

Hi All,
I have a Splunk environment which works internally using the IP address.
But when I tried accessing it externally on a site -sometimes dashboards are working and sometimes it's not showing anything just "Could not create search".
Is this caused by a network issue or Splunk configuration file?
Jobs are randomly stopped and show "502 error" on network inspect element.

alt text

esix_splunk
Splunk Employee
Splunk Employee

Most likely this is related to either a load balancer or application firewall/filter you are going through when you access this externally. Generally we recommend that in the case of load balancers, that you make sure sticky sessions are enabled or that you disable application filtering for the Splunk base urls.

0 Karma

jadengoho
Builder

Hi, esix,
What do you mean by "sticky sessions are enabled".
And how can I disable application filtering for Splunk base URL?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jadengoho,
some very stupid questions:

  • when you say "sometimes", are you saying that the same dashboard, sometimes run and sometimes goes in error or that any dashboards (always the same) go in error and any always run?
  • did you verified in your dashboard that all the configurations use IP address and not hostnames?

Bye.
Giuseppe

0 Karma

jadengoho
Builder

when you say "sometimes", are you saying that the same dashboard, sometimes runs and sometimes goes in error or that any dashboards (always the same) go in error and any always run? - sometimes panels works, sometimes not.. It always happens

did you verify in your dashboard that all the configurations use IP address and not hostnames? Yes we tried using IP address same issue

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jadengoho,
did you find the differences between the two kind of panels?
Bye.
Giuseppe

0 Karma

jadengoho
Builder

External Site: All panels show this error.
Internal Site: No error Exist.

We suspect that the error occurs on the load balancer or the firewall.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jadengoho,
are there firewalls between splunk servers?
anyway you can test the open ports between servers.

Why do you use a load balancer between Search Heads and Indexers? you don't need them: Splunk has auto load balancing features.

Bye.
Giuseppe

0 Karma

jawaharas
Motivator

Should be a network issue. Is it happening even if you try from different network (say your mobile network instead of WiFi) ?

0 Karma

jadengoho
Builder

Same network, but using the external address still shows the issue.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...