Getting Data In

Why am I getting "500 Internal Server Error" when I click "Data Inputs" under "Settings"?

benjamin009
Explorer

We have a fresh Splunk 6.3 install. We literally have 0 data currently indexing. When I click Settings -> Data Inputs. I am getting the error:

500 Internal Server Error
Return to Splunk home page
View more information about your request (request ID = tonsofnumbersandletters) in Search 
This page was linked to from http://x.x.x.x:8000/en-US/app/search/search.
You are logged into x.x.x.x:8000 as admin, which is connected to splunkd @ xxx

When I attempt to search error logs for the specific request ID, nothing populates. There is nothing in any of the error logs referencing this error. I have attempted several searches on Splunk Answers and this seemed to be a common thing for 5.x. I have yet to see a response that works with my issue. I also installed S.o.S (Splunk on Splunk) and do not see anything out of the ordinary that would cause this issue.

Both the search head and Indexer are CentOS 7 running with the user Splunk, not root. I am running out of ideas. Any help is appreciated.

P.S. When I go into Settings - Add Data. I am able to load that properly, but I am not able to view the data inputs.

1 Solution

benjamin009
Explorer

For those of you that are interested in the resolution. I (stupidly) disabled the splunk_httpinput app on the indexer. Once I re-enabled it, trying to add data worked just fine.

Dumb mistake by me. Dont be like me.

View solution in original post

kilama
New Member

I'm having the same problem here. No success with the splunk_httpinput trick. I got this on the splunkd.log:

07-22-2016 11:45:26.361 -0300 WARN  IConfCache - Error populating shared UserConfCache state: inputs /opt/splunk/etc/deployment-apps
07-22-2016 11:45:26.427 -0300 FATAL DeploymentServer - Attempted operation on uninitialized instance.
07-22-2016 11:45:26.427 -0300 ERROR DeploymentServer - Deployment Server is not available, because errors prevented its initialization. Please consult splunkd.log for details. You can try to reload Deployment Server after correcting these errors.

And some other logs/errors on web_service.log (Python tracebacks).

0 Karma

cjenglish99
Engager

This is exactly what I'm seeing, happens after I switch from Enterprise Trial to Free license.

0 Karma

cyndiback
Path Finder

I'm received the error but did not disable the splunk_httpinput app. I tried disabling and re-enabling the app. Did not help.

0 Karma

Jarohnimo
Builder

The account you are using is an admin on both boxes in splunk and on the boxes?

0 Karma

cpt12tech
Contributor

I'm also getting this message. My splunk_httpinput app was enabled, so I tried disabling, restart splunk, enable, restart splunk. Still can't view the data inputs. Next I tried enabling all the disabled apps. At one point I got a message saying I needed to reboot splunk from the CLI because the web interface wasn't working. I rebooted using the CLI, and now I can't connect to splunk using my web browser.

0 Karma

cpt12tech
Contributor

I got the webserver backup up by running
splunk webserver enable
still not able to access the data inputs

williamholder
Explorer

Hi mate,

Yup, that fixed it completely. It would have been handy if the error screen had some more relevant information to help track this down.

At least it's fixed now.

/B

0 Karma

williamholder
Explorer

it might have been a dumb mistake but you aren't alone - thanks for the answer.

Now I'm going to write that down somewhere for the next bunny that disables that app.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...