Installation

Why are searches stuck at "finalizing job" after upgrade to 6.5.0?

varad_joshi
Communicator

I upgraded Splunk on my linux server to 6.5.0 and after that no searches are getting completed. Not even index=_internal

Search job inspector also doesn't load.

All the jobs are getting stuck at 'finalizing job'. Tried bouncing Splunk web services as I was occasionally getting error as "Connection to Splunk server lost."

Any solution please??

Labels (2)
1 Solution

sgarvin55
Splunk Employee
Splunk Employee

search is always "parsing...." after upgrading to 6.5 from 6.3.2 - SPL-129476

This is actually caused by stale files remaining in cache after the upgrade. If you haven't all ready done so, try clearing browser cache and retry the search. This has helped quite a few customers reporting this issue.

View solution in original post

polymorphic
Communicator

Using Debian Jessie 64bit.
Also tested on Windows 10 64bit. No problems here.

//Jesper S

0 Karma

varad_joshi
Communicator

I did a few things that includes:

  • Restarting of Splunkweb services as I was also getting an error 'Connection to Splunk server lost'
  • Clearing dispatch directory

Cleared everything fro dispatch directory.

And after a while everything started working. I am not sure if that was the issue.

0 Karma

polymorphic
Communicator

Didnt work for me 😕

0 Karma

adepasquale
Path Finder

Restarting did not work for me either. I was not getting disconnect errors though.

0 Karma

varad_joshi
Communicator

Hopefully someone will have a concrete answer.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...