Installation

Why are searches stuck at "finalizing job" after upgrade to 6.5.0?

varad_joshi
Communicator

I upgraded Splunk on my linux server to 6.5.0 and after that no searches are getting completed. Not even index=_internal

Search job inspector also doesn't load.

All the jobs are getting stuck at 'finalizing job'. Tried bouncing Splunk web services as I was occasionally getting error as "Connection to Splunk server lost."

Any solution please??

Labels (2)
1 Solution

sgarvin55
Splunk Employee
Splunk Employee

search is always "parsing...." after upgrading to 6.5 from 6.3.2 - SPL-129476

This is actually caused by stale files remaining in cache after the upgrade. If you haven't all ready done so, try clearing browser cache and retry the search. This has helped quite a few customers reporting this issue.

View solution in original post

polymorphic
Communicator

Using Debian Jessie 64bit.
Also tested on Windows 10 64bit. No problems here.

//Jesper S

0 Karma

varad_joshi
Communicator

I did a few things that includes:

  • Restarting of Splunkweb services as I was also getting an error 'Connection to Splunk server lost'
  • Clearing dispatch directory

Cleared everything fro dispatch directory.

And after a while everything started working. I am not sure if that was the issue.

0 Karma

polymorphic
Communicator

Didnt work for me 😕

0 Karma

adepasquale
Path Finder

Restarting did not work for me either. I was not getting disconnect errors though.

0 Karma

varad_joshi
Communicator

Hopefully someone will have a concrete answer.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...