Installation

Blank Login Page

HMRCSplunk
Explorer

Hi,

So I have just installed splunk for the first time on my linux ubuntu machine. The only changes I have made during configuration is I have changed the HTTPS port in the web.conf file so that it uses port 12300 instead of 8000 port 8000 is being used by another program). I start splunk like usual and the output says that the ports are open and available to use and then links me the page of the splunk interface. When I click on the link it opens in my firefox browser and directs to the splunk web interface log in page. However nothing is displayed on the page.

I know that the web page is working correctly apart from its blank. The URL file structure changes to the log in page directory and I can also view the page source which is populated with what should be shown on the web page. I have also ran through the log files and there are no errors there either. Everything I have looked at looks like it should be running smoothly but it isnt. I have tried solutions on the internet like stopping iptables from running at the same time but I dont have iptables setup so this is not an cause.

If anyone has had and fixed this problem then please could you enlighten me as I feel like I have hit a brick wall with trying to install this.

Cheers

Tags (1)

HMRCSplunk
Explorer

Web_access.log, seems to GET all the necessary files according to the log but in the browser developer tab it says that it cant find the javascript files.

In web_service.log:

2018-01-12 10:19:45,126 INFO [5a588bc11eb535ad2c] error:133 - Masking the original 404 message: 'The path '/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD44E81AF17527B02/build/css/bootstrap-enterprise.css' was not found.' with 'Page not found!' for security reasons
2018-01-12 10:19:45,152 INFO [5a588bc126b531d1cc] error:133 - Masking the original 404 message: 'The path '/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD44E81AF17527B02/build/pages/enterprise/common.js' was not found.' with 'Page not found!' for security reasons
2018-01-12 10:19:45,157 INFO [5a588bc127b531d18c] error:133 - Masking the original 404 message: 'The path '/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD44E81AF17527B02/build/pages/enterprise/account.js' was not found.' with 'Page not found!' for security reasons
2018-01-12 10:19:45,221 INFO [5a588bc137b53683ec] error:133 - Masking the original 404 message: 'The path '/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD44E81AF17527B02/build/pages/enterprise/common.js' was not found.' with 'Page not found!' for security reasons
2018-01-12 10:19:45,230 INFO [5a588bc139b536824c] error:133 - Masking the original 404 message: 'The path '/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD44E81AF17527B02/build/pages/enterprise/account.js' was not found.' with 'Page not found!' for security reasons
2018-01-12 10:19:50,325 INFO [5a588bc652b536854c] error:133 - Masking the original 404 message: 'The path '/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD44E81AF17527B02/build/css/bootstrap-enterprise.css' was not found.' with 'Page not found!' for security reasons
2018-01-12 10:19:50,362 INFO [5a588bc65bb531d90c] error:133 - Masking the original 404 message: 'The path '/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD44E81AF17527B02/build/pages/enterprise/common.js' was not found.' with 'Page not found!' for security reasons
2018-01-12 10:19:50,367 INFO [5a588bc65db531df6c] error:133 - Masking the original 404 message: 'The path '/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD44E81AF17527B02/build/pages/enterprise/account.js' was not found.' with 'Page not found!' for security reasons
2018-01-12 10:19:50,438 INFO [5a588bc66fb536842c] error:133 - Masking the original 404 message: 'The path '/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD44E81AF17527B02/build/pages/enterprise/common.js' was not found.' with 'Page not found!' for security reasons
2018-01-12 10:19:50,447 INFO [5a588bc671b536866c] error:133 - Masking the original 404 message: 'The path '/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD44E81AF17527B02/build/pages/enterprise/account.js' was not found.' with 'Page not found!' for security reasons

This must be the problem, know anyway to fix this?

0 Karma

elliotproebstel
Champion

Is there any chance that you started splunk as root at one time and are now trying to start it as another user (perhaps "splunk")? I've seen errors of this nature after somebody started splunk as root. Assuming you are now trying to run it as "splunk", you might try shutting down splunk and then changing ownership of everything in the $SPLUNK_HOME directory by doing the following, as root:

$ chown -R splunk:splunk $SPLUNK_HOME

Then change over to the user "splunk" and try to start splunk again. If permissions were the issue, this should fix it.

0 Karma

elliotproebstel
Champion

Hmm, realizing that the $SPLUNK_HOME environment variable may not be set for the root user. If your installation was a vanilla install, then $SPLUNK_HOME will be /opt/splunk.

0 Karma

HMRCSplunk
Explorer

Nope cant see any .dmp files either.

Here is the last few lines of splunkd.log:

01-11-2018 14:23:32.488 +0000 INFO DatabaseDirectoryManager - idx=audit Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/audit/db', pendingBucketUpdates=0 . Reason='Buckets were rebuilt or tsidx-minified (bucket_count=1).'
01-11-2018 14:23:32.488 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/audit/db
01-11-2018 14:23:33.055 +0000 INFO IndexerIf - Asked to add or update bucket manifest values, bid=_audit~14~C94310F7-1F65-4765-8582-ED4C5D678114
01-11-2018 14:23:33.150 +0000 INFO ProcessTracker - (child_1
Fsck) Fsck - (bloomfilter only) Rebuild for bucket='/opt/splunk/var/lib/splunk/_internaldb/db/db_1515680600_1515679261_15' took 23.04 milliseconds
01-11-2018 14:23:33.487 +0000 INFO DatabaseDirectoryManager - idx=_audit Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/audit/db', pendingBucketUpdates=1 . Reason='Updating manifest: bucketUpdates=1'
01-11-2018 14:23:33.488 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/audit/db
01-11-2018 14:23:34.103 +0000 INFO IntrospectionGenerator:resource_usage - RU_main - I-data gathering (Resource Usage) starting; period=10s
01-11-2018 14:23:34.135 +0000 INFO IntrospectionGenerator:resource_usage - RU_main - I-data gathering (IO Statistics) starting; interval=60s
01-11-2018 14:23:35.164 +0000 INFO ProcessTracker - (child_2
_Fsck) Fsck - (bloomfilter only) Rebuild for bucket='/opt/splunk/var/lib/splunk/_introspection/db/db_1515680595_1515679261_14' took 22.17 milliseconds
01-11-2018 14:23:36.055 +0000 INFO IndexerIf - Asked to add or update bucket manifest values, bid=_internal~15~C94310F7-1F65-4765-8582-ED4C5D678114
01-11-2018 14:23:36.487 +0000 INFO DatabaseDirectoryManager - idx=_internal Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/_internaldb/db', pendingBucketUpdates=1 . Reason='Updating manifest: bucketUpdates=1'
01-11-2018 14:23:36.488 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_internaldb/db
01-11-2018 14:23:36.856 +0000 INFO TelemetryHandler - Telemetry Data Collection has been enabled for app=splunk_instrumentation for categories=License Usage.
01-11-2018 14:23:37.063 +0000 INFO IndexerIf - Asked to add or update bucket manifest values, bid=_introspection~14~C94310F7-1F65-4765-8582-ED4C5D678114
01-11-2018 14:23:37.488 +0000 INFO DatabaseDirectoryManager - idx=_introspection Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/_introspection/db', pendingBucketUpdates=1 . Reason='Updating manifest: bucketUpdates=1'
01-11-2018 14:23:37.489 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_introspection/db

0 Karma

HMRCSplunk
Explorer

01-11-2018 14:23:31.914 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/searchhistory.log'.
01-11-2018 14:23:31.945 +0000 INFO IndexWriter - Creating hot bucket=hot_v1_16, idx=internal, event timestamp=1515680601, reason="suitable bucket not found, number of hot buckets=0, max=3"
01-11-2018 14:23:31.946 +0000 INFO DatabaseDirectoryManager - idx=_internal Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/_internaldb/db', pendingBucketUpdates=0 . Reason='Adding bucket, bid=_internal~16~C94310F7-1F65-4765-8582-ED4C5D678114'
01-11-2018 14:23:31.946 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_internaldb/db
01-11-2018 14:23:31.949 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/export_metrics.log'.
01-11-2018 14:23:31.956 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/splunkd_stdout.log'.
01-11-2018 14:23:32.000 +0000 INFO WatchedFile - Will begin reading at offset=27305 for file='/opt/splunk/var/log/splunk/splunkd-utility.log'.
01-11-2018 14:23:32.013 +0000 INFO WatchedFile - Will begin reading at offset=1844 for file='/opt/splunk/var/log/splunk/splunkd_stderr.log'.
01-11-2018 14:23:32.039 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/mongod.log'.
01-11-2018 14:23:32.072 +0000 INFO WatchedFile - Will begin reading at offset=4440 for file='/opt/splunk/var/log/splunk/conf.log'.
01-11-2018 14:23:32.084 +0000 INFO WatchedFile - Will begin reading at offset=1339965 for file='/opt/splunk/var/log/splunk/audit.log'.
01-11-2018 14:23:32.117 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/django_access.log'.
01-11-2018 14:23:32.121 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/django_service.log'.
01-11-2018 14:23:32.488 +0000 INFO DatabaseDirectoryManager - idx=_audit Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/audit/db', pendingBucketUpdates=0 . Reason='Buckets were rebuilt or tsidx-minified (bucket_count=1).'
01-11-2018 14:23:32.488 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/audit/db
01-11-2018 14:23:33.055 +0000 INFO IndexerIf - Asked to add or update bucket manifest values, bid=_audit~14~C94310F7-1F65-4765-8582-ED4C5D678114
01-11-2018 14:23:33.150 +0000 INFO ProcessTracker - (child_1
Fsck) Fsck - (bloomfilter only) Rebuild for bucket='/opt/splunk/var/lib/splunk/_internaldb/db/db_1515680600_1515679261_15' took 23.04 milliseconds
01-11-2018 14:23:33.487 +0000 INFO DatabaseDirectoryManager - idx=_audit Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/audit/db', pendingBucketUpdates=1 . Reason='Updating manifest: bucketUpdates=1'
01-11-2018 14:23:33.488 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/audit/db
01-11-2018 14:23:34.103 +0000 INFO IntrospectionGenerator:resource_usage - RU_main - I-data gathering (Resource Usage) starting; period=10s
01-11-2018 14:23:34.135 +0000 INFO IntrospectionGenerator:resource_usage - RU_main - I-data gathering (IO Statistics) starting; interval=60s
01-11-2018 14:23:35.164 +0000 INFO ProcessTracker - (child_2
_Fsck) Fsck - (bloomfilter only) Rebuild for bucket='/opt/splunk/var/lib/splunk/_introspection/db/db_1515680595_1515679261_14' took 22.17 milliseconds
01-11-2018 14:23:36.055 +0000 INFO IndexerIf - Asked to add or update bucket manifest values, bid=_internal~15~C94310F7-1F65-4765-8582-ED4C5D678114
01-11-2018 14:23:36.487 +0000 INFO DatabaseDirectoryManager - idx=_internal Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/_internaldb/db', pendingBucketUpdates=1 . Reason='Updating manifest: bucketUpdates=1'
01-11-2018 14:23:36.488 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_internaldb/db
01-11-2018 14:23:36.856 +0000 INFO TelemetryHandler - Telemetry Data Collection has been enabled for app=splunk_instrumentation for categories=License Usage.
01-11-2018 14:23:37.063 +0000 INFO IndexerIf - Asked to add or update bucket manifest values, bid=_introspection~14~C94310F7-1F65-4765-8582-ED4C5D678114
01-11-2018 14:23:37.488 +0000 INFO DatabaseDirectoryManager - idx=_introspection Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/_introspection/db', pendingBucketUpdates=1 . Reason='Updating manifest: bucketUpdates=1'
01-11-2018 14:23:37.489 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_introspection/db

0 Karma

HMRCSplunk
Explorer

01-11-2018 13:50:59.218 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/introspection/db
01-11-2018 13:50:59.222 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/introspection/kvstore.log'.
01-11-2018 13:50:59.231 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/introspection/http_event_collector_metrics.log'.
01-11-2018 13:50:59.246 +0000 INFO WatchedFile - Will begin reading at offset=467998 for file='/opt/splunk/var/log/introspection/disk_objects.log'.
01-11-2018 13:50:59.253 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/remote_searches.log'.
01-11-2018 13:50:59.294 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/django_error.log'.
01-11-2018 13:50:59.301 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/searchhistory.log'.
01-11-2018 13:50:59.361 +0000 INFO IndexWriter - Creating hot bucket=hot_v1_14, idx=_internal, event timestamp=1515678649, reason="suitable bucket not found, number of hot buckets=0, max=3"
01-11-2018 13:50:59.362 +0000 INFO DatabaseDirectoryManager - idx=_internal Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/_internaldb/db', pendingBucketUpdates=0 . Reason='Adding bucket, bid=_internal~14~C94310F7-1F65-4765-8582-ED4C5D678114'
01-11-2018 13:50:59.362 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_internaldb/db
01-11-2018 13:50:59.371 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/export_metrics.log'.
01-11-2018 13:50:59.382 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/splunkd_stdout.log'.
01-11-2018 13:50:59.403 +0000 INFO WatchedFile - Will begin reading at offset=24933 for file='/opt/splunk/var/log/splunk/splunkd-utility.log'.
01-11-2018 13:50:59.415 +0000 INFO WatchedFile - Will begin reading at offset=1598 for file='/opt/splunk/var/log/splunk/splunkd_stderr.log'.
01-11-2018 13:50:59.429 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/mongod.log'.
01-11-2018 13:50:59.450 +0000 INFO WatchedFile - Will begin reading at offset=3848 for file='/opt/splunk/var/log/splunk/conf.log'.
01-11-2018 13:50:59.466 +0000 INFO WatchedFile - Will begin reading at offset=1320301 for file='/opt/splunk/var/log/splunk/audit.log'.
01-11-2018 13:50:59.515 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/django_access.log'.
01-11-2018 13:50:59.519 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/splunk/var/log/splunk/django_service.log'.
01-11-2018 13:50:59.725 +0000 INFO DatabaseDirectoryManager - idx=_audit Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/audit/db', pendingBucketUpdates=0 . Reason='Buckets were rebuilt or tsidx-minified (bucket_count=1).'
01-11-2018 13:50:59.725 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/audit/db
01-11-2018 13:51:00.243 +0000 INFO IndexerIf - Asked to add or update bucket manifest values, bid=_audit~12~C94310F7-1F65-4765-8582-ED4C5D678114
01-11-2018 13:51:00.372 +0000 INFO ProcessTracker - (child_1
Fsck) Fsck - (bloomfilter only) Rebuild for bucket='/opt/splunk/var/lib/splunk/_internaldb/db/db_1515678648_1515678534_13' took 16.08 milliseconds
01-11-2018 13:51:00.725 +0000 INFO DatabaseDirectoryManager - idx=_audit Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/audit/db', pendingBucketUpdates=1 . Reason='Updating manifest: bucketUpdates=1'
01-11-2018 13:51:00.725 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/audit/db
01-11-2018 13:51:01.357 +0000 INFO IntrospectionGenerator:resource_usage - RU_main - I-data gathering (Resource Usage) starting; period=10s
01-11-2018 13:51:01.379 +0000 INFO IntrospectionGenerator:resource_usage - RU_main - I-data gathering (IO Statistics) starting; interval=60s
01-11-2018 13:51:02.325 +0000 INFO ProcessTracker - (child_2
_Fsck) Fsck - (bloomfilter only) Rebuild for bucket='/opt/splunk/var/lib/splunk/_introspection/db/db_1515678648_1515678545_12' took 4.254 milliseconds
01-11-2018 13:51:03.243 +0000 INFO IndexerIf - Asked to add or update bucket manifest values, bid=_internal~13~C94310F7-1F65-4765-8582-ED4C5D678114
01-11-2018 13:51:03.725 +0000 INFO DatabaseDirectoryManager - idx=_internal Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/_internaldb/db', pendingBucketUpdates=1 . Reason='Updating manifest: bucketUpdates=1'
01-11-2018 13:51:03.725 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_internaldb/db
01-11-2018 13:51:04.111 +0000 INFO TelemetryHandler - Telemetry Data Collection has been enabled for app=splunk_instrumentation for categories=License Usage.
01-11-2018 13:51:04.243 +0000 INFO IndexerIf - Asked to add or update bucket manifest values, bid=_introspection~12~C94310F7-1F65-4765-8582-ED4C5D678114
01-11-2018 13:51:04.724 +0000 INFO DatabaseDirectoryManager - idx=_introspection Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/_introspection/db', pendingBucketUpdates=1 . Reason='Updating manifest: bucketUpdates=1'
01-11-2018 13:51:04.725 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_introspection/db
01-11-2018 13:51:29.306 +0000 INFO KeyManagerLocalhost - Checking for localhost key pair
01-11-2018 13:51:29.306 +0000 INFO KeyManagerLocalhost - Public key already exists: /opt/splunk/etc/auth/distServerKeys/trusted.pem
01-11-2018 13:51:29.306 +0000 INFO KeyManagerLocalhost - Reading public key for localhost: /opt/splunk/etc/auth/distServerKeys/trusted.pem
01-11-2018 13:51:29.306 +0000 INFO KeyManagerLocalhost - Finished reading public key for localhost: /opt/splunk/etc/auth/distServerKeys/trusted.pem
01-11-2018 13:51:29.306 +0000 INFO KeyManagerLocalhost - Reading private key for localhost: /opt/splunk/etc/auth/distServerKeys/private.pem
01-11-2018 13:51:29.306 +0000 INFO KeyManagerLocalhost - Finished reading private key for localhost: /opt/splunk/etc/auth/distServerKeys/private.pem
01-11-2018 13:51:59.726 +0000 INFO DatabaseDirectoryManager - idx=_internal Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/_internaldb/db', pendingBucketUpdates=0 . Reason='Buckets were rebuilt or tsidx-minified (bucket_count=1).'
01-11-2018 13:51:59.726 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_internaldb/db
01-11-2018 13:51:59.727 +0000 INFO DatabaseDirectoryManager - idx=_introspection Writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/_introspection/db', pendingBucketUpdates=0 . Reason='Buckets were rebuilt or tsidx-minified (bucket_count=1).'
01-11-2018 13:51:59.728 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_introspection/db

0 Karma

HMRCSplunk
Explorer

I am running linux ubuntu. This is the output from restarting splunk:

Checking prerequisites...
Checking http port [12300]: open
Checking mgmt port [12389]: open
Checking appserver port [127.0.0.1:8065]: open
Checking configuration... Done.
Checking critical directories... Done
Checking indexes...
Validated: _audit _internal _introspection _telemetry _thefishbucket history main summary
Done
Checking filesystem compatibility... Done
Checking conf files for problems...
Invalid key in stanza [settings] in /opt/splunk/etc/system/local/web.conf, line 37: xappServerPorts (value: 8066).
Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'
Done
Checking default conf files for edits...
Validating installed files against hashes from '/opt/splunk/splunk-7.0.1-2b5b15c4ee89-linux-2.6-i386-manifest'
All installed files intact.
Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...

Done

Waiting for web server at http://127.0.0.1:12300 to be available... Done

If you get stuck, we're here to help.

Look for answers here: http://docs.splunk.com

The Splunk web interface is at http://phishingpc-ESPRIMO-C700:12300

EDIT: Output from debugger:

Checking: /opt/splunk/etc/system/local/inputs.conf
No spec file for: /opt/splunk/etc/system/local/migration.conf
Checking: /opt/splunk/etc/system/local/server.conf
Checking: /opt/splunk/etc/system/local/web.conf
Invalid key in stanza [settings] in /opt/splunk/etc/system/local/web.conf, line 37: xappServerPorts (value: 8066).
Did you mean 'x_frame_options_sameorigin'?

0 Karma

nickhills
Ultra Champion

xappServerPorts (value: 8066)

looks like you have a typo (the x) which may be preventing splunk from starting - odd that it would report that it has started though.

If you run netstat -ln|grep 123 do you see entries for your two configured ports?

If my comment helps, please give it a thumbs up!
0 Karma

p_gurav
Champion

Hi HMRCSplunk,

Could you tell me what url you are accessing on browsers ? Try http://localhost:12300 OR https://localhost:12300

0 Karma

HMRCSplunk
Explorer

Hi, I'm accessing the web page by using the link provided by the terminal once you run the command to start the splunk server. So in my case, http://:12300. I have also tried using localhost:12300 and 127.0.0.1:12300 and still both give a blank screen.

0 Karma

p_gurav
Champion

Hi,
Could you share the screenshot?

0 Karma

HMRCSplunk
Explorer

A screenshot of what? my browser showing a blank screen?

0 Karma

p_gurav
Champion

Share the web.conf file where you did changed port?

0 Karma

HMRCSplunk
Explorer

[settings]

enable/disable the appserver

startwebserver = 1

port number tag is missing or 0 the server will NOT start an http listener

this is the port used for both SSL and non-SSL (we only have 1 port now).

httpport = 12300

this determines whether to start SplunkWeb in http or https.

enableSplunkWebSSL = false

location of splunkd; don't include http[s]:// in this anymore.

mgmtHostPort = 127.0.0.1:12389

list of ports to start python application servers on (although usually

one port is enough) Set to 0 to instead run the application server

directly as the web front end on 'httpport', separate from splunkd.

appServerPorts = 8066

This is the web.conf file saved in /splunk/etc/system/local.
All I have changed is the httpport and the mgmtHostPort

0 Karma

aljohnson_splun
Splunk Employee
Splunk Employee

do you see the same results on different browsers, with browser extensions off, and after clearing your web caches? are there http errors when you open the dev console in your browser?

0 Karma

HMRCSplunk
Explorer

Thanks for the reply.
I have tried running on firefox and chrome, both blank. I have turned off extensions and cleared web cache and still nothing.

This is the output i got from the dev console running on firefox:

Could not read chrome manifest 'file:///usr/lib/firefox/chrome.manifest'.
The resource from “http://phishingpc-esprimo-c700:12300/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD... was blocked due to MIME type mismatch (X-Content-Type-Options: nosniff).Learn More
The resource from “http://phishingpc-esprimo-c700:12300/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD... was blocked due to MIME type mismatch (X-Content-Type-Options: nosniff).Learn More
The resource from “http://phishingpc-esprimo-c700:12300/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD... was blocked due to MIME type mismatch (X-Content-Type-Options: nosniff).Learn More
Synchronous XMLHttpRequest on the main thread is deprecated because of its detrimental effects to the end user's experience. For more help http://xhr.spec.whatwg.org/ config:1:13
The resource from “http://phishingpc-esprimo-c700:12300/en-GB/static/@7F44362F43575C23315E176660629FD2339C79AAD3986A3FD... was blocked due to MIME type mismatch (X-Content-Type-Options: nosniff).Learn More
Loading failed for the

0 Karma

mayurr98
Super Champion

hey try opening ports in linux firewall
https://www.tixati.com/optimize/open-ports-linux.html

let me know if this helps !

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...