Security

clicking on data inputs shows 500 internal server error

cpt12tech
Contributor

When clicking on the data inputs link in the splunk settings I see an error
500 Internal Server Error

In the web_service log I see this error
InternalServerError: [HTTP 500] Splunkd internal error; [{'text': "\n In handler 'http': Deployment Server is not available, because errors prevented its initialization. Please consult splunkd.log for details. You can try to reload Deployment Server after correcting these errors.", 'type': 'ERROR', 'code': None}]

I'm running a single indexing server, free license and not using a deployment server

I tried entering the command
disable deploy-server
and got the message
current license does not allow the requested action

I'm not using the serverclass.conf in the local folder

Tags (1)
1 Solution

ppablo
Retired

Hi @cpt12tech

Thanks for bringing attention to this issue on Splunk Answers. A bug was filed the last week of July and is tracked as a known issue under SPL-124923: Selecting Data Inputs under Settings results in a "500 Internal Server Error" in Splunk Enterprise 6.4.2 on a Forwarder or Free license.
http://docs.splunk.com/Documentation/Splunk/6.4.2/ReleaseNotes/KnownIssues#Splunk_Web_and_Home_inter...

The fix for this bug is expected in the upcoming 6.4.3 release. The current workaround is to downgrade to 6.4.1 for instances with a Forwarder or Free license.

View solution in original post

ppablo
Retired

Hi @cpt12tech

Thanks for bringing attention to this issue on Splunk Answers. A bug was filed the last week of July and is tracked as a known issue under SPL-124923: Selecting Data Inputs under Settings results in a "500 Internal Server Error" in Splunk Enterprise 6.4.2 on a Forwarder or Free license.
http://docs.splunk.com/Documentation/Splunk/6.4.2/ReleaseNotes/KnownIssues#Splunk_Web_and_Home_inter...

The fix for this bug is expected in the upcoming 6.4.3 release. The current workaround is to downgrade to 6.4.1 for instances with a Forwarder or Free license.

cpt12tech
Contributor

Upgrading to 6.4.3 resolved this for me! I can access the data inputs using the Web GUI.

0 Karma

ppablo
Retired

Awesome, thanks @cp12tech for updating the thread and confirming the upgrade helped resolve the issue 🙂

Cheers
Patrick

0 Karma

inventsekar
Ultra Champion

maybe check this one...
https://answers.splunk.com/answers/356955/why-am-i-getting-500-internal-server-error-when-i.html

For those of you that are interested in the resolution. I (stupidly) disabled the splunk_httpinput app on the indexer. Once I re-enabled it, trying to add data worked just fine.

0 Karma

cpt12tech
Contributor

That did not work for me. splunk_httpinput is enabled for me. I disabled, then enabled and did not help. It did stop the web server, which I started back up by typing in
./splunk enable webserver

0 Karma

somesoni2
SplunkTrust
SplunkTrust

Check if there are any configuration errors in your instance. Run this. If any error found fix them and restart Splunk.

splunk btool check --debug

0 Karma

cpt12tech
Contributor

correction
ran the splunk start --debug
and no errors found
when I ran btool check --debug
I do see one error
No spec file for: C:\Program Files\Splunk\etc\system\local\migration.conf

0 Karma

cpt12tech
Contributor

Ran the --debug, no errors found

0 Karma

sundareshr
Legend

What do you get when you type this query

index=_internal sourcetype=splunkd err* 
0 Karma

cpt12tech
Contributor

07-14-2016 19:51:12.106 -0600 ERROR DeploymentServer - Deployment Server is not available, because errors prevented its initialization. Please consult splunkd.log for details. You can try to reload Deployment Server after correcting these errors.

0 Karma

sundareshr
Legend

If you not using the DS, delete etc/deployment-apps directory and remove the serverclass.conf from local folder (do not delete from default folders)

0 Karma

cpt12tech
Contributor

Followed the instructions, deleted the folder and the blank serverclass.conf file. Restarted splunk, went to data inputs, no change in the problem. Verified the error showed up in the splunk errors index.

0 Karma

taiyed
New Member

I am also seeing this issue on Splunk 6.4.2 (Free License). I get the following error when looking in the _internal index for errors

"ERROR DeploymentServer - Deployment Server is not available, because errors prevented its initialization. Please consult splunkd.log for details. You can try to reload Deployment Server after correcting these errors."

0 Karma

andersson
New Member

I have the exact same problem. I tried deleting the etc/deployment-apps directory but it made no difference.

0 Karma

cpt12tech
Contributor

Glad it's not just me. Thanks talyed.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...