We have a fresh Splunk 6.3 install. We literally have 0 data currently indexing. When I click Settings -> Data Inputs. I am getting the error:
500 Internal Server Error Return to Splunk home page View more information about your request (request ID = tonsofnumbersandletters) in Search This page was linked to from http://x.x.x.x:8000/en-US/app/search/search. You are logged into x.x.x.x:8000 as admin, which is connected to splunkd @ xxx
When I attempt to search error logs for the specific request ID, nothing populates. There is nothing in any of the error logs referencing this error. I have attempted several searches on Splunk Answers and this seemed to be a common thing for 5.x. I have yet to see a response that works with my issue. I also installed S.o.S (Splunk on Splunk) and do not see anything out of the ordinary that would cause this issue.
Both the search head and Indexer are CentOS 7 running with the user Splunk, not root. I am running out of ideas. Any help is appreciated.
P.S. When I go into Settings - Add Data. I am able to load that properly, but I am not able to view the data inputs.
For those of you that are interested in the resolution. I (stupidly) disabled the splunk_httpinput app on the indexer. Once I re-enabled it, trying to add data worked just fine.
Dumb mistake by me. Dont be like me.
it might have been a dumb mistake but you aren't alone - thanks for the answer.
Now I'm going to write that down somewhere for the next bunny that disables that app.
Yup, that fixed it completely. It would have been handy if the error screen had some more relevant information to help track this down.
At least it's fixed now.
I'm also getting this message. My splunk_httpinput app was enabled, so I tried disabling, restart splunk, enable, restart splunk. Still can't view the data inputs. Next I tried enabling all the disabled apps. At one point I got a message saying I needed to reboot splunk from the CLI because the web interface wasn't working. I rebooted using the CLI, and now I can't connect to splunk using my web browser.
I got the webserver backup up by running
splunk webserver enable
still not able to access the data inputs
I'm received the error but did not disable the splunk_httpinput app. I tried disabling and re-enabling the app. Did not help.
The account you are using is an admin on both boxes in splunk and on the boxes?
I'm having the same problem here. No success with the splunk_httpinput trick. I got this on the splunkd.log:
07-22-2016 11:45:26.361 -0300 WARN IConfCache - Error populating shared UserConfCache state: inputs /opt/splunk/etc/deployment-apps 07-22-2016 11:45:26.427 -0300 FATAL DeploymentServer - Attempted operation on uninitialized instance. 07-22-2016 11:45:26.427 -0300 ERROR DeploymentServer - Deployment Server is not available, because errors prevented its initialization. Please consult splunkd.log for details. You can try to reload Deployment Server after correcting these errors.
And some other logs/errors on web_service.log (Python tracebacks).
This is exactly what I'm seeing, happens after I switch from Enterprise Trial to Free license.