Splunk Enterprise

Splunk deployment server GUI bug

skyred5
Engager

Hello!

I have recently upgraded my splunk enterprise servers from 9.1.2 to 9.2.1. I noticed the following web behaviors in deployment server ;

1. When searching for hostname, it takes a long time to load
2. Server class and app for (any) host is not reflecting correctly. This was crossed checked on CLI serverclass.conf 

 

Wondering if anyone face this issue and if it is a GUI bug.

Labels (2)
0 Karma

deepakc
Builder

With the new version, there are a number of changes, have a look through this doc, in short, you need to ensure a number of new indexes are in place _ds* see the doc and there's another setting in the output.conf of the deployment server and add the new whitelist indexes to the UF's. Try these if it still fails log a support call.

https://docs.splunk.com/Documentation/Splunk/9.2.0/Updating/Upgradepre-9.2deploymentservers 

0 Karma

skyred5
Engager

Hello,

 

Thanks for your response. I have added the necessary configuration according to the article that you shared. But we are still facing this issue. 

The UI loading is slow as well.

 

0 Karma

deepakc
Builder

If you done that, then best course or action might be log a support ticket, as there could be another underlying issue.    

0 Karma
Get Updates on the Splunk Community!

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...