Splunk Enterprise

Splunk Heavy Forwarder UI is not loading

Karthikeya
Communicator

Hello we have installed Akamai add-on on our HF and giving necessary monitor stanzas on its inputs.conf. we are using config explorer where we will perform all on-boarding actions from frontend itself. But somehow our HF UI is not loading at all these days frequently. Rest all components with same config explorer working fine. Not sure what is the issue. There are no errors found in splunkd.log. can someone help me with this?

Labels (2)
0 Karma

squinlan2
Explorer

Although it probably doesn't explain the intermittent nature of the problem, I've seen fapolicyd interfere with some Splunk Add-On UI pages.  If this were the case you would need to configure an fapolicyd exception.  You can audit fapolicyd using the command: sudo /usr/sbin/fapolicyd --debug-deny

Hope this helps!

0 Karma

Karthikeya
Communicator

Karthikeya_0-1758031390750.pngKarthikeya_1-1758031406189.png

 

0 Karma

Karthikeya
Communicator

this is happening frequently. Sometimes it will load fine sometimes it won't load like now. When I am checking web_service.log, I see these errors 

2025-09-16 13:03:58,859 ERROR   [68c960398b7f172e20e210] util:598 - unable to parse embed_uri as URL: Invalid entry for setting : embed_uri
2025-09-16 13:03:58,859 INFO    [68c960398b7f172e20e210] root:355 - Proxied mode ip_address=127.0.0.1 port=8065 exposed_port=8443:
2025-09-16 13:03:58,963 INFO    [68c960398b7f172e20e210] root:619 - overriding JSON MIME type with 'text/plain; charset=UTF-8'
2025-09-16 13:03:58,971 ERROR   [68c960398b7f172e20e210] startup:116 - Unable to read in product version information; isSessionKeyDefined=False error=[HTTP 401] Client is not authenticated
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you verified the web server is enabled?

splunk btool --debug web list | grep startwebserver
---
If this reply helps you, Karma would be appreciated.
0 Karma

Karthikeya
Communicator

I am running this in bin and no results is coming.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I fixed the command.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Karthikeya
Communicator

/opt/splunk/etc/system/default/web.conf startwebserver = 1

UI loaded till yesterday but we have this issues frequently. Not sure what's the issue is.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...