Splunk Enterprise

Splunk Heavy Forwarder UI is not loading

Karthikeya
Communicator

Hello we have installed Akamai add-on on our HF and giving necessary monitor stanzas on its inputs.conf. we are using config explorer where we will perform all on-boarding actions from frontend itself. But somehow our HF UI is not loading at all these days frequently. Rest all components with same config explorer working fine. Not sure what is the issue. There are no errors found in splunkd.log. can someone help me with this?

Labels (2)
0 Karma

squinlan2
Explorer

Although it probably doesn't explain the intermittent nature of the problem, I've seen fapolicyd interfere with some Splunk Add-On UI pages.  If this were the case you would need to configure an fapolicyd exception.  You can audit fapolicyd using the command: sudo /usr/sbin/fapolicyd --debug-deny

Hope this helps!

0 Karma

Karthikeya
Communicator

Karthikeya_0-1758031390750.pngKarthikeya_1-1758031406189.png

 

0 Karma

Karthikeya
Communicator

this is happening frequently. Sometimes it will load fine sometimes it won't load like now. When I am checking web_service.log, I see these errors 

2025-09-16 13:03:58,859 ERROR   [68c960398b7f172e20e210] util:598 - unable to parse embed_uri as URL: Invalid entry for setting : embed_uri
2025-09-16 13:03:58,859 INFO    [68c960398b7f172e20e210] root:355 - Proxied mode ip_address=127.0.0.1 port=8065 exposed_port=8443:
2025-09-16 13:03:58,963 INFO    [68c960398b7f172e20e210] root:619 - overriding JSON MIME type with 'text/plain; charset=UTF-8'
2025-09-16 13:03:58,971 ERROR   [68c960398b7f172e20e210] startup:116 - Unable to read in product version information; isSessionKeyDefined=False error=[HTTP 401] Client is not authenticated
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you verified the web server is enabled?

splunk btool --debug web list | grep startwebserver
---
If this reply helps you, Karma would be appreciated.
0 Karma

Karthikeya
Communicator

I am running this in bin and no results is coming.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I fixed the command.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Karthikeya
Communicator

/opt/splunk/etc/system/default/web.conf startwebserver = 1

UI loaded till yesterday but we have this issues frequently. Not sure what's the issue is.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...