Splunk Enterprise

Why are there Issues after updating to Splunk Enterprise 9.1.1?

TheExpert
Path Finder

Hi all,

today I updated Splunk enterprise from 9.0.5 to 9.1.1. Since the update I see the folliwing messages on the start page:

"Laden der App-Liste nicht möglich. Aktualisieren Sie die Seite, um den Vorgang zu wiederholen."

and

"Laden von gemeinsamen Aufgaben nicht möglich. Aktualisieren Sie die Seite, um den Vorgang zu wiederholen."

Reloading the page doesn't solve the issue. A reboot of Windows where Splunk is installed doesn't help either.

Splunk seems to work fine. But do you have any ideas how to solve the issue?

Thank You.

Labels (1)
Tags (1)
0 Karma

TheExpert
Path Finder

With the update to Splunk enterprise 9.1.3 everything is looking fine. There are no more 

messages on the start page:

"Laden der App-Liste nicht möglich. Aktualisieren Sie die Seite, um den Vorgang zu wiederholen."

and

"Laden von gemeinsamen Aufgaben nicht möglich. Aktualisieren Sie die Seite, um den Vorgang zu wiederholen."

0 Karma

TheExpert
Path Finder

And with the update to Splunk Enterprise 9.2.0 the issue came back again :-(.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Please create a support ticket to splunk.
0 Karma

TheExpert
Path Finder

I'm a user of the free Community Edition. So I can't open support tickets, right?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Unfortunately that’s true.
0 Karma

TheExpert
Path Finder

With Splunk Enterprise 9.2.1 there's no issue any more. This issue is defintively related to the builds of Splunk Enterprise.

0 Karma

TheExpert
Path Finder

Hi all,

today I tried to reinstall Splunk but this doesn't solve the issue.

Then I uninstalled Splunk with losing all data. So I installed Splunk again but then all settings were lost. I restored the data, apps and settings from my backup. After some issues with the certificates and the admin password I was able to get Splunk running without issues.

But the data inputs weren't configured. So I restored the inputs.conf of the search app where the data inputs are configured. After restarting Splunk the issue came back again and for my surprise there was no login as admin anymore. Before I had to login with the admin user after each restart of Splunk.

Deleting the inputs.conf doesn't help.

So I have now researched for many hours without resolving the issue and I've lost data of a day :-(.

Can anyone assist, please?

Thank You.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Probably the easiest way is go back to situation when you have done fresh installation and everything is working. Then just add inputs one by one and see which one broke your environment. 

This is annoying and long time taking process, but still I thing that this is the easiest way.

0 Karma

TheExpert
Path Finder

I don't understand what the inputs have to do with the issues on web UI of Splunk. And before the update to 9.1.1 there were no issues like these. I think there's a bug with 9.1.1 causing these issues.

If there would be a way to rollback by changing the inputs.conf file I would be fine testing this again. But repeating all the steps I had done yesterday is indiscutable. This is time wasting!

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Have you checked that your Windows version is supported by Splunk 9.1.1? 

As you could see from https://docs.splunk.com/Documentation/Splunk/9.1.1/ReleaseNotes/Deprecatedfeatures#Removed_features_...

Windows 2016 has removed from supported OS version.

r. Ismo

0 Karma

TheExpert
Path Finder

Thank you. And what about Windows 10 22H2? Looking on the download page this OS release is still supported:

TheExpert_0-1693565621331.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

TheExpert
Path Finder

So I've running Splunk Enterprise on a supported system, Windows 22H2, 64 Bit.

But how can I solve the issue regarding the app and task list?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Did you found anything from splunkd.log or _internal index?
0 Karma

TheExpert
Path Finder

What should I search for in splunkd log? And how can I check _internal index?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Anything what could related to that error/warning.

From _internal logs you could try e.g.

index=_internal sourcetype=splunkd source=*/splunkd.log ERROR OR WARN

select suitable time for search e.g. when you have started splunk. 

0 Karma

TheExpert
Path Finder

Thank you. In splunkd log there are so many errors. I'm wondering that Splunk is working. But this is not related to the newest update. I see that these errors were also logged in the previous release. But I don't find errors related to this issue.

With

index=_internal sourcetype=splunkd source=*/splunkd.log ERROR OR WARN

I also don't find any errors or warnings.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...