Security

Server error below the search bar

thippeshaj
Explorer

Hi Splunkers,

Need you help to fix the below problem.

We recently migrated our standalone search head to the cluster search head and after that we started seeing server error. After running a search that returns results, if left for just a little bit, the message “Server Error” will pop up below the search bar. I suspect that this is related to the apache proxy ( our authentication method, Apache proxy that is sitting in front of the Splunk webserver) as well as I haven’t seen it happen when using the username/password auth method.

And I have seen similar issue posted but there it was a browser issue but in my case it is not related to browser issue as I have tried on all the browsers and I have faced the similar issues on all.

Thanks in advance,
Thippesh

0 Karma

ericlarsen
Path Finder

Did you ever find a resolution for this error?  We're running v7.3.2,  search head cluster, indexer cluster.

It doesn't appear to affect the searches running, but multiple users are getting the "Server Error" message, usually after the job has finalized.

Thanks.

0 Karma

deepashri_123
Motivator

Hi thippeshaj,

Can you look for errors in the splunkd.log
Run the query below:
index=_internal log_level=ERROR and look for the errors.
That might help giving you a better insight.

0 Karma

thippeshaj
Explorer

Hi deepa,
I have tried all the basic troubleshooting, didn't workout.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...