Security

Server error below the search bar

thippeshaj
Explorer

Hi Splunkers,

Need you help to fix the below problem.

We recently migrated our standalone search head to the cluster search head and after that we started seeing server error. After running a search that returns results, if left for just a little bit, the message “Server Error” will pop up below the search bar. I suspect that this is related to the apache proxy ( our authentication method, Apache proxy that is sitting in front of the Splunk webserver) as well as I haven’t seen it happen when using the username/password auth method.

And I have seen similar issue posted but there it was a browser issue but in my case it is not related to browser issue as I have tried on all the browsers and I have faced the similar issues on all.

Thanks in advance,
Thippesh

0 Karma

ericlarsen
Path Finder

Did you ever find a resolution for this error?  We're running v7.3.2,  search head cluster, indexer cluster.

It doesn't appear to affect the searches running, but multiple users are getting the "Server Error" message, usually after the job has finalized.

Thanks.

0 Karma

deepashri_123
Motivator

Hi thippeshaj,

Can you look for errors in the splunkd.log
Run the query below:
index=_internal log_level=ERROR and look for the errors.
That might help giving you a better insight.

0 Karma

thippeshaj
Explorer

Hi deepa,
I have tried all the basic troubleshooting, didn't workout.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...