Splunk Enterprise Security

500 Internal Server Error-Response Not Ready

garima_chauhan
Path Finder

Hi,

I have ES APP (v 2.4.1) installed on Splunk (v 5.0.5) on Windows machine.

Machine details-

Processor- 2 GHz
RAM -7.50GB
System Type- 64-bit OS

After installation and initial configuration of the ES App, when I try to login into Splunk or browse through the tabs(after logon), I get the following error:

500 Internal Server Error
ResponseNot Ready

However, after refreshing a number of times, I get the following:

An error occurred while rendering the page template.See web_service.log for more details.

After refreshing the page repeatedly, Splunk Web console is displayed but with a solid red bar either on top of the page or above/below the time chart. I have tried changing the SPLUNKD_CONNECTION_TIMEOUT = 60 instead of its default value of 30 in $SPLUNK_HOME\Python2.7\site_packages\splunk\rest_init_.py but it did not work.

Please suggest as to what could be wrong here and how to rectify it.

0 Karma
1 Solution

ShaneNewman
Motivator

Look at the login page. If it says SPLUNK_VERSION=UNKNOWN, then you need to bounce the entire server. If you have WS2003R2 64-bit, this will be a common occurrence for you. The Cache is filling up and the server is loosing connectivity with the domain server. You can confirm that this is the issue if you check the WMI logs and see a ubroker error.

View solution in original post

0 Karma

ShaneNewman
Motivator

Look at the login page. If it says SPLUNK_VERSION=UNKNOWN, then you need to bounce the entire server. If you have WS2003R2 64-bit, this will be a common occurrence for you. The Cache is filling up and the server is loosing connectivity with the domain server. You can confirm that this is the issue if you check the WMI logs and see a ubroker error.

0 Karma

garima_chauhan
Path Finder

The login page does not display SPLUNK_VERSION=UNKNOWN. The windows server I am using is WS2008R2 64 bit.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...