I upgraded Splunk on my linux server to 6.5.0 and after that no searches are getting completed. Not even index=_internal
Search job inspector also doesn't load.
All the jobs are getting stuck at 'finalizing job'. Tried bouncing Splunk web services as I was occasionally getting error as "Connection to Splunk server lost."
Any solution please??
I did a few things that includes:
Cleared everything fro dispatch directory.
And after a while everything started working. I am not sure if that was the issue.
Now i actually tried to wipe the entire Splunk installation, and install from scratch.
(It is only a test installation)
Still having the same issue.
Could this maybe be an OS issue?
trying to update
No change after update.
Also tried the suggestion from @ddrillic. Still no change.
What OS you are running? I see no mention of Win 7 while downloading executable.
Also I already heard it giving issues on Win 7 32 bit machines.
Using Debian Jessie 64bit.
Also tested on Windows 10 64bit. No problems here.
A related discussion at dispatch.finalizeRemoteTimeline taking a long time?
It says there -
-- When I run a search in Splunk 6.x, the results come back quickly, but it seems like a lot of time is spent on "Finalize Job". When I look at the search inspector, it shows that a lot of time is spend on "dispatch.finalizeRemoteTimeline".
An answer by @abhijitmishra says -
Hmm seems to be the search app which gives the problems...
Searches run fine in other apps.