Security

Why does my Splunk Web interface stop responding after a few hours?

jackal713
Path Finder

Hello Splunkers,

I seem to be having an issue where the web interface stops responding after a few hours. I then must issue "splunk restart" to bring it back but it stops working again after awhile. It is still indexing during that time. It's just that the web interface will not respond until I restart Splunk.

Thanks in advance. Other info below.

Splunk status when it is not working shows: "Splunkd: Running (pid ###)"

After Splunk restarts, it shows the same thing with a different PID number.

Splunkd is the only thing it lists in either case.

After the restart is complete the the web interface works just fine. For awhile.

OS: Win 10 Pro

0 Karma

jackal713
Path Finder

I think I found the issue. We recently updated to Avast Business Pro antivirus. This version has it's own firewall that DID NOT copy existing exceptions from Windows Defender firewall. Creating exceptions in Avast did not resolve the issue. After several posts on the Avast help forum, the easiest (only?) way to fix this is to turn off Avast firewall and revert to Windows Defender firewall.

After doing this, Splunk works as intended until Avast is restarted and automatically re-enables the firewall. To prevent this you must (from the Avast management console) create a new settings template with Avast firewall disabled and apply it to the Splunk server.

Hope this helps others that may run in to this same issue.
Happy Splunking.

Splunk>Your data.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...