Splunk Enterprise

Splunk Heavy Forwarder UI is not loading

Karthikeya
Communicator

Hello we have installed Akamai add-on on our HF and giving necessary monitor stanzas on its inputs.conf. we are using config explorer where we will perform all on-boarding actions from frontend itself. But somehow our HF UI is not loading at all these days frequently. Rest all components with same config explorer working fine. Not sure what is the issue. There are no errors found in splunkd.log. can someone help me with this?

Labels (2)
0 Karma

squinlan2
Engager

Although it probably doesn't explain the intermittent nature of the problem, I've seen fapolicyd interfere with some Splunk Add-On UI pages.  If this were the case you would need to configure an fapolicyd exception.  You can audit fapolicyd using the command: sudo /usr/sbin/fapolicyd --debug-deny

Hope this helps!

0 Karma

Karthikeya
Communicator

Karthikeya_0-1758031390750.pngKarthikeya_1-1758031406189.png

 

0 Karma

Karthikeya
Communicator

this is happening frequently. Sometimes it will load fine sometimes it won't load like now. When I am checking web_service.log, I see these errors 

2025-09-16 13:03:58,859 ERROR   [68c960398b7f172e20e210] util:598 - unable to parse embed_uri as URL: Invalid entry for setting : embed_uri
2025-09-16 13:03:58,859 INFO    [68c960398b7f172e20e210] root:355 - Proxied mode ip_address=127.0.0.1 port=8065 exposed_port=8443:
2025-09-16 13:03:58,963 INFO    [68c960398b7f172e20e210] root:619 - overriding JSON MIME type with 'text/plain; charset=UTF-8'
2025-09-16 13:03:58,971 ERROR   [68c960398b7f172e20e210] startup:116 - Unable to read in product version information; isSessionKeyDefined=False error=[HTTP 401] Client is not authenticated
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you verified the web server is enabled?

splunk btool --debug web list | grep startwebserver
---
If this reply helps you, Karma would be appreciated.
0 Karma

Karthikeya
Communicator

I am running this in bin and no results is coming.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I fixed the command.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Karthikeya
Communicator

/opt/splunk/etc/system/default/web.conf startwebserver = 1

UI loaded till yesterday but we have this issues frequently. Not sure what's the issue is.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...