- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk deployment server GUI bug
Hello!
I have recently upgraded my splunk enterprise servers from 9.1.2 to 9.2.1. I noticed the following web behaviors in deployment server ;
1. When searching for hostname, it takes a long time to load
2. Server class and app for (any) host is not reflecting correctly. This was crossed checked on CLI serverclass.conf
Wondering if anyone face this issue and if it is a GUI bug.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm encountering an issue in the Forwarder Management Console.
When navigating to the GUI and clicking on a server class, the clients are not visible. However, if I click "Add Clients," they become visible. Additionally, under the Clients tab, while I can see the clients listed, it doesn't display how many apps are deployed on those clients. The server class indicates that 4 apps are deployed on 30 servers, but the Clients tab shows zero apps deployed on those clients.
Can someone provide a proper solution for this issue?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I haven't confirmed myself, but I believe this issue is resolved in 9.2.2.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Version:9.2.1Build:78803f08aabb
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
we are experiencing the same behaviour. CPU Load, disk space, RAM etc looks fine... Have you been able to solve the issue?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
With the new version, there are a number of changes, have a look through this doc, in short, you need to ensure a number of new indexes are in place _ds* see the doc and there's another setting in the output.conf of the deployment server and add the new whitelist indexes to the UF's. Try these if it still fails log a support call.
https://docs.splunk.com/Documentation/Splunk/9.2.0/Updating/Upgradepre-9.2deploymentservers
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Thanks for your response. I have added the necessary configuration according to the article that you shared. But we are still facing this issue.
The UI loading is slow as well.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm seeing the same behavior after upgrading the 9.2.1 and including the new indexes, any update on this?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you done that, then best course or action might be log a support ticket, as there could be another underlying issue.
