Splunk Search

Splunk Search Heads in infinite loop of refreshing

dkrichards16
Path Finder

We had one search head have to be rebuilt because of JAVA issues.  We had another search head, due to a network switch outage, loose connection to the search head cluster.

When we re-adding those servers to the search head cluster we not have a strange issue with where custom apps can't search.  They either provided a "error fetching saved searches" in the panel then get stuck in a infinite loop of refreshing the browser tab or they load an error 255 where they can't search indexes even though they can search indexes fine in the default search and reporting app.

We use custom authorization.conf and authorize.conf configs in /opt/splunk/etc/system/local and affected servers have the latest configs copied from a healthy server.  I'm working with splunk support but they are requesting har browser files and the issues seem to be permissions related.  Has anyone else seen this issue and able to resolve it?

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...