I upgraded Splunk on my linux server to 6.5.0 and after that no searches are getting completed. Not even index=_internal
Search job inspector also doesn't load.
All the jobs are getting stuck at 'finalizing job'. Tried bouncing Splunk web services as I was occasionally getting error as "Connection to Splunk server lost."
Any solution please??
search is always "parsing...." after upgrading to 6.5 from 6.3.2 - SPL-129476
This is actually caused by stale files remaining in cache after the upgrade. If you haven't all ready done so, try clearing browser cache and retry the search. This has helped quite a few customers reporting this issue.
I did a few things that includes:
Cleared everything fro dispatch directory.
And after a while everything started working. I am not sure if that was the issue.