Did 2 upgrades 1 on a physical server and 1 on a Virtual Server.
The only difference between the servers is that on the Physical server the indexes are in the default location and on the Virtual server they are in a specific directory /splunkdb.
After upgrading splunk on a physical server I am unable to view any data. I search on source="who" which has 4 entries and get the search page - auto pausing window pops up to finalize search. "Your search is finalizing...." This runs for approximately 3 minutes and then I receive "Your network connection may have been lost or Splunk Web may be down". Checked and splunkweb is running. The search is still running. Unable to get off this screen. The only way to get off the search screen is to restart the splunk server.
I have ran the clean eventdata on the database with no help.
Any assistance would be greatly appreciated.
Where can I look for further information?